{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2a39481f-4888-5a44-b4b2-f9e3e713c8b2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.31-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d2991d64-deed-5374-adb6-1c6f1aac909a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e35f9028-2c54-54ec-b8f0-fb993c04d65f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4358c6c7-6778-5d0b-8f22-1c3cc35995ef",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dfe61bd-b59a-58d9-8b1f-bca5bbbf3e5a",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005c0834-c159-528a-81ca-2189b3eb0c1f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b974132-658b-5025-9442-4d05f14662bc",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:698f35db-b97a-50d0-bf31-45174f15a0d8",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01ae518-d78d-5517-8bcd-4ed5206e8bb8",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d599fb37-d234-5a1e-babd-ee9644ba1122",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c413306c-fb0b-598e-9b9b-793e3286227d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b24e45f-0718-5f87-bed9-e9448b64a56e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6494618e-9fa5-5a1b-bc3b-0a6c4dd9ede7",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-tx 5.3.31-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c20bda-d144-5ca8-871b-9a2b90fe023c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e361ec4-584a-5d0a-b71f-7e016ed46dc3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d0ca802-f97c-594d-af90-42f2815cda0c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02de5542-5734-59bd-a3f5-c3bb747682bd",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2725ae5d-8505-56b7-a055-030944f74e35",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d101326-3288-570e-bdef-0ee437885f76",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:132eb479-ec63-5cb9-9460-1ab9a80f4e1e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4b45b31-f76d-5c53-8448-aed0a29e186d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690c65b6-a8d8-5675-a327-6541feaeae93",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03871f2a-1a4b-530b-958b-6133915750bc",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b24b38b-5bf5-5f1c-9c79-c49b2a486a3d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.5 of org.springframework:spring-tx. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0288b0f-fc8f-510f-b598-e2ea2ec4e9ba",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c061b923-b9fa-528a-b4ad-f9e9db9b61fa",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e25c34ce-90fd-5a23-8768-f738307ea578",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab90d9d3-767d-5c62-b25f-4804717e52d0",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5cbabb3-07b1-538a-b14d-1f29ceb13c47",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eeaa23d-16fd-5dd7-818b-4d57c2eb90e9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e6f3554-4228-5080-85a5-06f1cf58191c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75467435-ca71-55b7-b18f-6d2c8541ad82",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e41c9c5-bc00-5a8e-9e82-54d97111e63d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e97d95aa-ca89-59bf-b941-8644a1c1422d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b18d571-864f-52f8-a551-df3d0a05d354",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:650b7f1a-b75b-5430-b4ff-023ba3560157",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cd8d397-adc7-55c7-b614-0c9ec77b8a8e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a26d3614-f07d-53ef-ad19-f923f3443db9",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.5 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.5"
    }
  ]
}