{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:943ce694-6a4f-5307-bd4b-db8a29fd14b9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.30-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e28a97d1-0e9d-5875-82a2-3964356c9dde",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e685265a-a313-5c6c-aa99-5d5a3ad5d1b2",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c885068-2f40-5dd7-b202-71fe63332f0a",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:318d5551-b473-5966-a0fb-1e75a29fff2f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d21f6b4-c3a2-51b6-b9ab-74d5ac855af4",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195c6bae-ed91-5003-a844-7aa6f4fe89a4",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6f3ce76-88b8-55c8-889b-56a207fbd8d5",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f85ee9fd-3f1a-59dc-a879-bd4c7ddd6443",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:811492e9-e2e8-56a3-9225-2d2c517432d8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c22c770-4879-5200-8e1d-43b556518228",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d50a317-150f-5c3c-b5bb-e96e05f42893",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed15d8fb-9481-5922-bd54-5f8789c1c941",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e164192e-b367-5510-a890-01019d0d8f99",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:471a2234-f832-5acf-99f4-8effbecc474f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c4e5a98-99b9-59ba-9ff9-1839c0f66759",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7f2d3b9-bc25-5e36-91e5-a176e275ae21",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0001b9-2fe4-58af-a882-5eb6ddb8918c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14dcd443-5c2c-5f4f-98aa-53a984f36bdc",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52deca83-c491-546e-beb6-d53e63dccb64",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:107ef987-b5ab-5598-957f-36aa469b5859",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf9564f-6b1b-5527-bf46-62a84dbe82c8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb490b0-f989-5ba6-a91a-2b1e97cd8e72",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.4 of org.springframework:spring-tx. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5ec9901-0551-59e8-bdcf-b9bc525fca6a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de232150-660f-5a42-8226-5dd254ce8c8b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0570a33b-5004-5612-9d44-606df84b985f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c2b69c5-f354-58e9-ac2f-3873cf5e4f99",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc9d9cfc-d082-525d-8220-18fded14bbe3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b1e5b96-b145-598a-a6e8-8e40f162f59d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb1f600e-ceb8-558f-8c54-bfccaf23b2cd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0babbafe-f999-5a07-a405-618022223764",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4ab9584-2a76-5438-b6a5-f4d53f5e727d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c24fa5-d967-591b-95cd-ee215678ea6c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf12c43-02ee-5d84-8d87-bb9c98ccc0cd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96b5e28e-7f44-5e6d-a26f-4a55e90cdcee",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ae0afd5-49f8-5954-865b-fef251581848",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dc83800-4a8c-53df-856b-d3738ec01ce7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.30-tuxcare.4"
    }
  ]
}