{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:79728607-06bc-58a4-8f20-b7e3ce9d2f40",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.27-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:46cf721d-7345-53eb-b3a1-76b0ccae7aaa",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e871d8-3c49-5496-9dda-8e5d0d9e8494",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a65133b-71cc-5974-8b78-d5f11f79f389",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db063dd8-16e9-5d99-a0b3-681d0e12488b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f243cf95-a7b6-5da2-a936-a4ba8c3c8e55",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71cd858c-8d02-5382-bc42-a4c15aaaa6d8",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d78d877-3411-578b-93d3-de1a73609830",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff645f6-bac1-5d2f-989b-4e5c0ec02c4d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cd8342f-6537-5758-aaed-b7b2e519e5dd",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f40f75-47fb-56e3-bfd4-aaee67a0a351",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe7b0fa-02d5-558f-a077-de18b0c210c0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1821d925-d14b-56d2-9189-b30c93bdfc18",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.27-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1b031f-5152-587f-9659-94c57e1cdf4c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a923d021-2233-53a0-9444-487533b120c3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6ff08b-1935-525b-884f-939604da244c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e5661d-b260-5559-985e-aeb1d87153fd",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f1726ef-d935-5a69-b94b-f6eaf60d3613",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696d5595-982c-56df-a355-3b6f42d9758c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47699208-c195-5e2b-8f9e-95e9236d3609",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbfe654a-2aa9-5e06-979a-a87af29bd313",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba7b818-c354-5f61-9a0d-8a93480cdf29",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d413cd7-9da0-5d64-87a9-38df8d65d802",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e5a2c91-a636-5151-8c7c-d7bf68900a22",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21f3f2d8-4155-59b1-89d2-056d9e7ad596",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:925a2786-b4de-506b-bcb9-51a24558e3c3",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffdebea1-ee6f-522e-b3ff-8ccfd3ac3c48",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b1ea605-9196-5214-97f3-434394ab8952",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745632fd-2ac6-5407-9209-56dc69618de0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e7479f4-f783-5f7b-b674-c35fa03cdeef",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:278a7883-43c3-5413-a716-808d6ae0b8b7",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-aop. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cd65e6-b64e-5706-b942-c0d6a7a16b27",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53a3c970-40f8-5600-b1f7-fe27653c51bf",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1f2abc-f47a-57db-8e11-acee70b08bd2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b00483b8-9fbd-54b8-8ff2-c3755fd73a5f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fddf2172-e969-5b32-b74c-396d6dc1b7ff",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91b1d726-b84a-5fae-8a3e-7fabbd6307b9",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd7381ce-6f84-5da1-a4bf-8c67a294025b",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ba7e1b-8c2a-5c82-88d0-611007bf0f1e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.7"
    }
  ]
}