{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6d69a439-a280-5ce9-acca-ea822a60e432",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "5.3.37-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0d675afc-125a-5805-a0fc-15eeff40fd4e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1aa76ed-6d96-5698-b56e-53b744d36184",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df23f4f-92f2-5e17-bdfc-da87006e4785",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a87fcaea-d721-5a10-864f-633e6d735728",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e121f81f-98f0-5347-9897-03dd0e29123a",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0cf3e7-80fe-5706-b1d0-de43d331f599",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6a38cb3-5701-5493-a843-1cb200352a48",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce440c9b-ee9a-5b9b-b1ba-4921ea93fa95",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f87c992-ed7c-55aa-8d6f-a09883d51113",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bf0a7cd-dc3f-5a7a-b1b9-dc888afb5067",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07848696-555b-5839-99bf-1ee22138dc86",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62f26130-00aa-5e33-bcb0-8f1450b08f23",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23cdb93e-1f1a-5918-ae04-9fe94271a4ce",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbf9d5a5-3287-5075-b2c7-6ac6321463bd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce73d7c2-bd17-50a1-9ee1-7e7019f9a5a5",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecfe43f9-b1fc-56e3-9d78-df9fb50b16f6",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f463fd7e-a342-5b3d-aa4b-ff72c0c3b84f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4555b68f-bd80-51b7-8176-0bc3c7ab8e9d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bac4d25c-e35c-59b5-b2db-9cee4c7b4f57",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fc9b0c2-5a38-593f-8600-9db195a9cb14",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13940106-9521-51d3-991b-f08976c80132",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fa9118b-6086-5189-904e-155efc5e8cd8",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8073bf29-d457-5bee-a728-4f9f8850ae58",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8241808-1ee5-5089-be36-20b6a00b7590",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38ddf577-9bab-5fea-803f-d74c141743ee",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e13ac86-73fd-56de-bff8-c12c1b4ece14",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d35fd5-1733-504b-a313-30a09bc58d18",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aca173df-c738-5ae3-a688-203d68dbe934",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d4995b-ebe1-544d-9186-d0160ad21ab8",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49d1e0db-fece-5abc-b0f4-b6cf1021295c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e40ea8f-5c6a-58f2-bd5b-2b189df48f00",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b84f00e8-56c6-5ef8-b31a-df681d1ccef7",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287ddd58-9d9d-5d6f-8985-70d970ced98a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.7 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.37-tuxcare.7"
    }
  ]
}