{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7561f9df-561b-597f-aff9-ec974f1f25a5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "5.3.30-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:aa384eec-fe0a-51f6-b624-5a74313e3608",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e05dfee9-a11b-5bed-a365-fcf56c5f0589",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b0d982-df7f-5b4d-a2e9-5fedcc25b2b8",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0551d0c9-4323-5df5-b6d0-cb99a857a905",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca635b1e-2563-5d35-baf4-c081e6e1b222",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55a70f37-05bc-5ae5-b8d5-1b5561cd8f93",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e2743af-6183-5170-8360-f8c4dc97c93b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2300b957-9f49-5daf-9087-afa0e45c198f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dcd9235-1ddf-5e78-86ff-c3d16abb1a65",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be972d5-e0fd-5f48-a9e4-063da0a8f615",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7ac3845-8b77-5a33-9075-6724f0b73d1b",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da639fe6-9240-5486-86b1-91ebb056fabf",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:222fce4b-5f55-5750-8eb7-3c32cf7b6fdf",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285ee26b-9a0c-5195-aa3d-33ef8647ccbd",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b28459-c121-5876-b972-b2f508bcc0e8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:428d8b68-9618-5a1b-85d4-719370966ecc",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e294ea75-c4ce-5248-a935-5ccd1dc94b57",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d2b3487-5cd3-5501-a6c4-ae27add8d09c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99311d9-0d6d-5f42-8a46-306fa9b7856b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed706fba-45cd-57dc-8a51-a1bad2ed1fc0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96fb9be8-8299-58c5-9d51-79c0d3d752cc",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fe7461f-775b-59d5-95da-6da7209b9079",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.2 of org.springframework:spring-oxm. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:069e078e-061e-5ba1-bfe0-c6499aa990df",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4da86b63-fe65-5626-a463-72a0ccffa98f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e640c868-13ca-5979-a29a-4566082b7415",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9867a7f2-c232-56ad-ad29-76afd1193a47",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd12df10-5077-52d9-b3d9-270440c6b0b2",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700324fd-cdd8-5b4b-9d67-64d3a4fc1be4",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e74a083-1551-529b-a153-7ed1345da54f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:578086f5-775d-57fa-85d8-95dc03cd21cf",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881c7b11-c6e9-5a27-8f87-0e6c394a2174",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8678241e-c3b8-5df1-93ef-1351cc05ad8c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c112049-83a8-5ec0-a814-1295b7d070b0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bad111da-1dd3-5d49-ad55-5c6e16af54cd",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46cc8938-d4a1-580f-bea3-4036389230b6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb7f341f-9c8c-5219-a74d-f22b59f9e208",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.2"
    }
  ]
}