{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c5d39851-ffbd-5b27-a631-eceda8753d66",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "5.3.37-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:defe4ccc-3932-5ba9-a33a-062ccd47ec88",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ded8279d-5815-5873-bb7e-a43571065561",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f87c1b-b730-59fc-8e6a-621038eef7fb",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17cc926f-4d5d-516f-a067-a8685176ebdf",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83793055-c0ab-50b9-8207-eb308e5938fb",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ab075c3-a5df-54a8-8359-c4a4b14a1b22",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75bb21bd-5e4c-5900-a1d2-3a2ec8b0b3d8",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df086940-f4cf-5fd8-84c3-bb3de0b96fea",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b5cee9b-f062-5cb3-aace-83f3a794c442",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128d01de-f95c-51bf-b648-2174df7982c7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c58b44-7d64-5bdf-8b1f-85165f63a202",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58925f5f-a046-5f69-bcef-e3190b5ca5b6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a16c5ac1-e1ae-5726-988b-28c86800ef41",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d9749f1-3e41-5e75-9685-89ff453034dd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0284a217-ffdc-52f0-be74-4e9b41e9eaa9",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3d8eddf-7769-5120-8f37-b4eabe013a7b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21c05bf0-1b0a-5e3e-ba60-6fd7b0a1f58b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd0ab465-969f-54be-9660-441ea6a13d62",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5f925f-2fd7-500f-af6c-32b74a95d816",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1808bdcb-2148-5b95-bc11-bb59e50acfe3",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f7b029-da0f-557e-8cb2-c5f156c7148e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ed26a7-f414-5e2d-92d8-89887f9d4f3f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e42bbfe9-2ce7-541a-ac99-3833a4d0ecc3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff9ceca8-25af-52e6-a516-a56cb6701c8d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae2e82fa-2aee-5ace-9b6b-27ca22e7c53b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1b9df1-4619-5b33-bc9b-23c8cb0aa90e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da2f029f-344d-5797-9e27-b1dee83ce5eb",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51c1d980-0360-5ba6-a407-be34a22a2713",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93c1133c-dbea-5553-b4aa-bbc456a3b732",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1a8e645-2b52-502a-8c94-20623c4f232f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a9caa47-6109-56ee-b6f7-9ce0e4fc76ea",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9674d41a-043f-58f8-aa67-a916b5d8813a",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4410e831-33c5-5513-9ecc-b60ec3af726c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.5 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.5"
    }
  ]
}