{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a1281434-78ba-5545-8132-b25c70d1c356",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.37-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e6992727-81b2-587a-8021-c69dea6ef074",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a6e1e6-83be-533e-a391-7e0edd3dfe87",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9af98ab-7c29-571f-9f6e-bb1b5e1bc2ee",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bec31497-7d50-5f02-bda0-1ca62f39c498",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802d1daf-268f-51e7-84a9-1bdbc75cf7ec",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:402e805a-fb95-53e7-8dc0-6aa27bea4e6b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f19bf2b-81a7-5933-b0eb-8798eeaae500",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0018d24-b183-5584-a2a1-64e10c7c1683",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13b84057-b4d9-560e-89fc-e04e4c5301e6",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba01f97-7669-5b98-a931-96ee0e755bfc",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63bd85ec-c9cd-5882-92f6-639a06333234",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75b13592-2b5d-50d2-9d86-03ad68110d93",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d89203-c744-5873-a2fd-8bc7cacfa206",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fa69747-2f9b-586d-a6bf-6ac9d54802cc",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:548b4dc7-6f19-5cda-82ac-37feb57369ad",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b045083c-15dc-55ef-9591-f09a09e86b44",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fcd2ea9-1e34-5045-ac4a-29084f2aa3a1",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ca61ab-6e97-5f14-bffd-a950843844fe",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b3d957d-0a38-5a71-a724-f5b9d54baca8",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:803f0519-871b-5064-bcf9-d3978caa7837",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b28b877-445c-5b5e-9161-d8fcfa12be2d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6453a01a-fcb4-5d22-af85-f8c4f479ec48",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4088864-0660-51d4-ac73-c6cba3660a8f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635f6fa7-b073-5423-9faa-e30c319aadf8",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f116eef5-2dbc-5a63-8abb-3851753f09d0",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7291dde7-3756-5b86-89eb-f50e0993185f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:211411e3-5705-5a0e-9e11-8e0f3143af5d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26f29157-2e7d-548a-8e39-0eeb464c8b98",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-aop. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:424698dd-b26f-5461-916d-7c9eaf32cbe1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b827591f-e4a0-59dc-be96-ecd2923ebc6e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0deced3a-03e7-511e-9748-308650aee141",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53be1897-9f42-5c8a-8d75-f4aa7d8f3045",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f28f2be2-6e72-51b2-9c04-b3f8765bff90",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-aop. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4286998b-ffb1-5ecf-8ae0-92cf3c2093a2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.9"
    }
  ]
}