{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6305f88d-2186-5482-a99a-6144fcef6779",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "5.3.37-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0feaff3d-3131-5467-ad3a-6eaf83433a3c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a8f03c-053f-5b13-978a-4933d7754c94",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d137343f-99da-5f2f-9eff-a22295a66f2f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:816d8644-75d3-5d56-96b2-1e9e772707cd",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7df8e34-08ae-5699-94cc-bb1d61121af0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d8cb3c-1bd9-568a-803f-e1acaac6b8b4",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f44f12d4-d53d-5058-b6cc-294bac7dbbdc",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef9d1b9d-ae0e-5a25-b96a-fd8109452319",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4972e697-acfb-5bd6-8e54-adfb56c7aaf9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d175ba-b126-5aca-9286-31153a5244be",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5da44541-6c7f-5cb5-aae9-1620f8d765e2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba39c32-044a-592f-903b-342f4d22e2e1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd35595-f2b6-5aa3-b9c4-d3f19f4c2a4d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e440e080-79a0-5ea9-9b4f-ea37d50b33f8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b44342ec-caf0-5104-a0f2-d8f12f588890",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ee182dd-c70f-55ea-9b8b-cac509ca5991",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391f87ca-7f87-5173-9821-3c7c2a18ff35",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8097088-61da-5c36-92cb-c653dd3bd89a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eae61f62-fd2c-5f8f-b9fe-a29190b43b0b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bddbb7-0401-575c-b966-4a43e6c56ce7",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3caf53a1-ce75-5d65-bf00-280801f48253",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0be450c-d75d-5575-98d0-31d370d1afbd",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2bce1fb-a9d2-5803-a1f5-24112fb5b633",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3d910b6-5545-577d-a112-89efab8129dd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44cf9ac5-5d8a-5b7f-8b39-e6fcf0615302",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14325fc-347e-5209-93f7-dfd3c1d2c62b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d204a53-6102-564e-9577-4e799798c159",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:707c36ca-80db-593d-b4d9-e4a67de273e9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-aspects. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40a0daef-ad69-5454-aad9-9938229a95e1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d180f5c3-3a70-5865-98ce-cf304767e202",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca66444-28fa-5d36-9021-2a425f55d142",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c869f9-55ce-525e-b7ff-901208b92d91",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d58232a-ac54-5152-a8ca-09d8e0ed37f8",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.7 of org.springframework:spring-aspects. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f56c0d-b3c0-5e37-8b4d-77074ef67574",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8883003-d878-54e3-9491-7580b9646dfb",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4b2023f-0952-5c81-ba8e-77307670d4d1",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:674c7287-34bb-58b8-90e1-0024c994d4ae",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16109ca9-3c36-5995-b539-4a234e9f8197",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0b765fe-ecb0-5ddd-8a8d-f61b574408e2",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7904a95a-67f9-54cf-91c9-1c0fc270b391",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ac37e82-3ad9-51c6-b91f-6866be941d75",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c488f012-9488-5862-b53b-6a8a473b92d9",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2063e7c-b6b4-5652-84ec-3994ab7834c2",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63d558db-7705-553e-a0c3-411ac9ac559f",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e38d763-e708-5bb3-8f47-6772ea49ef57",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be234736-1eaa-5c14-990d-90a84222b5ce",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c90a133-6162-5e8b-a373-16b75f938dab",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@5.3.37-tuxcare.7"
    }
  ]
}