{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3e8f3131-b190-5c4a-b5c3-10b4bd0f22c1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.31-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:874458b1-3f98-5fab-bad3-fa34b2c24138",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e2f903-71e1-5aa4-bead-479f068f5661",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1def11b7-c2e7-5388-9d24-ed4f60f381c4",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:210fddac-cbf9-5d3d-9666-3fc1cb5e1943",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecadea11-ca0a-556f-8ecf-4b35e91ce3e3",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b7c004c-44bd-5acb-b2b5-53425421f584",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c060b0-e8ac-51e7-9c7a-ebec9cb49309",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e43be28b-8cda-574a-bc10-ecb9c2cfeb04",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7b5a8c-fbe5-53d9-bf08-9f889b7ff04b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:104dbf4f-6816-539a-95fb-120b034db174",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e8f1e60-0ac8-5b90-b762-919e71b345b3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18043e56-75dd-5ea4-9505-f224c0b77c5c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.31-tuxcare.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db281cf8-7011-5067-b76d-9642d9cfe4b9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e559d99-3230-5220-b3ea-1d07116015cb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec77c4e1-3443-5cac-99a5-413d72020ab9",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1876869-1ad4-571b-9578-eb7506fc77e9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2baee78d-21fe-5e48-b600-364de52b8fdd",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b264455-60f8-55f4-b6af-31290450e571",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34aa7f0e-6074-5c23-a0a7-a648d991d22c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0166b006-d633-5da2-af7c-55df9b89b3e0",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945a06d3-67e9-5341-a2e8-b56412a308f7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe29941-bc64-525c-b3fb-42dee6967d58",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d6f4312-e06c-5a3a-8619-22f16f1fcdbe",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.10 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fd6da7c-f0f2-5b65-a27d-bd6f707e0fc6",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4ca6629-ccb1-5221-8341-bf30545b1870",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d64d90e-19ea-5e99-be50-1fc546b6b1fe",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dbc6af2-b608-54f7-89d8-6756103e1597",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd881d65-b530-501b-bf91-253df76946ec",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a39d82a-d08a-5160-8d51-af939d014c4c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ac99897-4a9f-58c5-8f61-135a75625ac9",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f30e9974-2664-5dd0-936f-3b0f971073b7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:654a67c1-3de7-53a4-a998-464b6d1a3984",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b4cc2c-474f-5cf1-bef9-a0ae74e3e8e6",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:168ccfe8-25f4-5583-b7a9-3853bdd0addd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f523ca5e-0ecb-5a53-83f0-6ba895ceac08",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c6cb69-ad30-5fc0-8ae4-490750e6d911",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbef8080-d12d-55b6-ab84-37b95521478c",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b473d4e-6863-5df8-b1a0-1ea0786209a3",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.31-tuxcare.10"
    }
  ]
}