{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4868d6ae-0035-5d64-9dff-cd1ecb92bd88",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "5.3.37-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ed625314-1d32-588d-a501-b10615cd5740",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e3a777-2f4f-547e-b82c-83623bcf4cc8",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08d0ec4a-c5e4-53ef-bf47-4e0c16e0bb84",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82d9337-bf68-598c-84d4-47c7d3f05811",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7975344f-fa54-57c7-932f-d8c97a4a3d73",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e86912-dd40-5934-879d-cc9b4741948f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a836521-d6ed-5e67-b0b9-105b536a5c62",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:057b1bfa-b43f-5aad-91b3-400155137700",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41f45858-da08-5c4c-83a4-3056f8fbc336",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eee9d9b-f2a1-5aab-acfe-971c64730619",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33524d0d-8d40-5c51-8189-5a68b5cbe0a2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71dfd2a3-9376-5cd0-818f-6eaee3f1c3e7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc7f8d11-bdf1-547d-bd0e-2326ff6bc138",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba73081-1843-5de8-ae79-e24115c55ca2",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e14fa6ea-5c5e-57cd-bf19-e783d19e13a1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b721e61d-053b-5f11-bf7f-834bf459a55d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.4 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.37-tuxcare.4"
    }
  ]
}