{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8d74ff35-1c02-5a86-bda7-32742a793c76",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.30-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e02d63c5-f029-564c-91bc-42ded63c6640",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26646daa-5906-5dbe-ab82-d3cbf56c0adc",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc05aabc-727a-56bf-9571-1b1f20002574",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:979c3fdd-3ab5-50eb-ae4f-34f9767ed8e0",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:925dd127-b992-5d69-b19c-03ecd1e7ac27",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6925b3c-ea5d-5157-bd31-2d1a6dabf741",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fb69146-35b4-5d40-b314-d252d92e94df",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5cc753a-97db-5f46-8b55-4758cf33641d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58a2b3e3-2c66-52e6-918c-bc5af37f6d40",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7365b8c6-39b0-50f2-b428-b5473eddbed1",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bc96e31-ebe5-5bfc-b8bc-f95b8d197db8",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d11d681e-e9e1-50b2-94bc-79fea4765728",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:093cc4cb-5272-5005-ae98-38db230516e7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eb8dbca-0967-5333-80bf-90bcdb8caaf8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:756e112d-cda3-501e-813f-348403d8d02a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06955868-11cf-58f7-9f0d-479b57f99254",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1351c1f2-dfa6-50fc-8bb3-6fe981f3e90e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd3f8f0a-d38d-532e-9fee-31112d6089e5",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57e7f83e-1bf4-516c-86cd-6a4e5480931d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1a05c4-7f1a-5c12-a29c-d841a32e9706",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a94928c-c664-5b18-aac9-f0ac1c076f7b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ecd0d7-5af8-5655-bcee-5600de60b354",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.2 of org.springframework:spring-tx. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca47cf00-5db7-53cc-95ec-b7e6b9888ec8",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f843806-290a-561a-a497-bc1b6456fbc9",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbdb4e14-dd9a-5960-9d9c-94cd8321ddd7",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a473aa9-52fa-5213-94ce-a7694e3ca310",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e9f92b1-9426-5ad1-9d96-c6bbf96b0241",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d08a4248-7d3c-5118-8bc5-7ba6d21108db",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdfdc599-f84d-5442-8e19-f32fe015ceac",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:829e8f5c-2a99-5754-ba2e-e38ca24f32e9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab274550-887b-5eae-ab26-900a59d02a2d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a015cc2-ead8-5f63-8461-4d47582f22af",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da3974c6-5d29-5863-8fb4-f39cc13f8d78",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55868055-8e2c-571c-8fba-d310ae60fa63",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:106e4b51-b96b-5cf5-ad48-1bd31e0a0da5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796940ed-a82c-5811-9088-b055614be691",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.2"
    }
  ]
}