{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:feb185f8-84d2-5565-ad31-4f1cea962b6d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.39-tuxcare.13",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dc30487d-322f-5907-930d-7c0551016615",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61fc2642-cc49-57c3-a51a-c634d76ca6c3",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-tx. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab372d6-0b08-5c9f-a156-a62f3fd7809b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:662b0370-61fc-5a7f-a23d-33110632b378",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:584deb1e-76f1-5cbe-be1c-370fb8067953",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3757512f-e425-52e9-b47b-ebf714fceeeb",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00872d75-6de2-5c83-8cdb-77dbc92c32cf",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3dc452-edd6-50e5-90a9-b505c96e1345",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-tx 5.3.39-tuxcare.13."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee21714-c7c9-5dc5-813d-ab06db853dea",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:012e4ac0-2ab2-5a20-97f8-1e29858607dd",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d3b7a5-d27a-5b06-85ad-c19f119510db",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3c55141-ae09-5081-a88e-7f18589b8920",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed4b788-df12-50e4-aef3-dfbf95a5366b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06134ad2-f46b-55b4-a97d-6efe621fa0bc",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b25ff98-7cd4-5ee8-96d6-ce60314c922e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff7245f5-dacf-50ec-bca2-506abc878416",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4064e5d-2259-5d63-aa1b-a55037c5101a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b54baca-81fa-5204-84ee-add65817df0a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01586ac1-60bf-5331-833a-17891c51dbc0",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-tx. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e6384f-78f8-58fe-83f3-7a74a0b709b5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb6646e-1d1c-51e3-a443-1fc7198f7ea5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a76d92-7dc3-5430-943e-bf92b928eb6f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dba4566f-a307-52ff-9bab-1b5672e1a9d7",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bcd755c-0d3e-5e16-b5d8-3aec89618978",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d8850d-f854-59d5-9a46-50e7f48a741e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68010c3a-858b-5a24-b336-0581c67336cb",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e6d6eb6-6207-5970-84a0-d59bca4abac0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3c5a4d-b150-5d53-b2f1-495729295f1b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe77dea-7050-55b4-b344-1557f3ea1ef1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a56b6778-3f05-570e-8449-3299d240d12e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d16c573-cf23-5abd-b5a7-c3f3f2934b7c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:843faffa-7c2e-59b5-a9f3-b480073f7d27",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc7a4d4c-e6d8-5d59-9b0c-975535fb0fce",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.13 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.39-tuxcare.13"
    }
  ]
}