{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c9374ab6-3053-50cc-83f4-566e82d91d7e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.30-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ecb47264-0c88-5f5a-b8c0-7e058c874503",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f4d3aac-34d0-5a22-a4a1-fc53c56b669b",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fdc89ba-1a83-5d8e-ba63-eee565d5ad8a",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1f2cc5-edc7-5c27-b813-5efd2fdf899b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0847058c-3860-549c-8d76-c5add04e9411",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a1b2c94-de2a-5511-9022-c79c09480c0d",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be3831e9-c067-5fd7-ad0c-22bd2ff3dd0f",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:670c09b2-3f09-5dd4-b17f-0cc989a9e0d1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb5cfa25-fb3b-5a82-9abb-171a15cbefae",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c3aac5-02e8-5691-985f-a58b142bae9b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ebefc08-0cb0-5879-8ad1-f6e98540b06b",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8d40257-40cb-5e2c-8e53-6c6333b5f0c1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b32be8-bd0a-5387-87ef-df4f6a05d7c8",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5857e78-c593-54c0-9f11-707a658893fa",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78f676fe-92bc-5913-8cc1-954b51fefac2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c57aca-8bc8-5dc5-9a0a-bb6df945e0c0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:938254a4-4b77-5d59-ad83-7dccb5ae352f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45091119-16cb-5dba-a75e-e6c799583c51",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb2d58a-63a8-5d96-9d3c-81271c2b3d94",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:994441d1-35b2-574a-9d35-e41847b84cd1",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c275029e-dded-55dc-a1ef-69115c5ee1c5",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da063c54-83fa-536a-a5d9-aff245f7dd29",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.6 of org.springframework:spring-aop. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eee4e205-d77e-5429-959d-94d6006fab28",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b58cd027-6f1e-538f-bb00-11336ef7f288",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e01381c6-e8ec-55b6-97cb-c8c91f516490",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2048d120-b528-59fd-933e-09d6612dbb90",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f61792f-c8be-544f-accb-378983c574ff",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fe3e1dc-f6ba-5db4-b4a5-2c8ec8637d8b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3500a2ee-58f5-5ee7-b685-447130d87674",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9606806d-a18e-537f-bc61-c7e4313a8ac3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdbd65b-aca2-5ae3-9a66-ab4850cceaec",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00006ef7-6a97-57ce-9ba1-1d6a0859cd0c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c421323-5d22-51b1-b2b6-1cc4dd52d772",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc28a775-4f82-5988-94f8-a95225e30b79",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c925b1d8-f180-5dd5-b74c-4151d64fac34",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da17c9a1-5bde-5093-b05d-d1caafa75ada",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd3e8dc4-d4e6-5c24-b5b1-7b4983e6b572",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.30-tuxcare.6"
    }
  ]
}