{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9143e276-65b7-5eec-8c4a-d4ecb73d013f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "5.3.27-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4e7a5204-d489-54dd-b6bc-328c060e0228",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe441b67-dc9f-5886-9c0e-b13a02c8e6ff",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ea1b2c-7888-55ff-b0e2-41027597e983",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f178a593-a2de-52dd-b4b1-66fca9a343ff",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b230643-4d38-5178-b051-5e88ccb70735",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b1b7f29-8650-5af8-9f53-0694d64699a2",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b02bf4-463b-57d5-985c-cf1863010c26",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab0de02-1ab7-56b6-b9f8-b66584df11d4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bceb05a-a41e-5f7f-9e5f-365a14956cf5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2419fbb9-024d-54fb-81b7-3ed8b340708c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55323e55-72e9-5372-b195-1269854f8603",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3051214-748d-585f-b5d5-3fc870a44091",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aspects 5.3.27-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d147fa6-1fac-54a7-aaa1-c11cb623ab65",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d9cd7e-d988-5526-9e0e-715f384aa7cc",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26fc2363-8cef-502a-b35c-f5f1b337f73f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cf024f9-c27e-5427-b787-5ed2bc4de090",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224cb4c3-3a4c-5698-a1b2-e045a9683783",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a455b944-8a38-59e1-8a6d-c8c76e30d6a4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01981143-e1e9-530b-8831-dca004fc00e6",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a808548-5789-52d9-bb92-8f14b6397165",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:842de540-8595-5cf4-833f-17901eff57b1",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69be1841-b8bf-5b8f-95f7-123700d9bc94",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbfcb686-0228-5bf3-8a3a-71d8cc803894",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb808729-237b-57b1-91b6-d2b70a034de2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2e10712-8684-52ac-8aaf-dfcc72d022eb",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c522925a-cc08-5087-a4a4-e944e72b8b7c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28a6206c-98a8-558d-9db7-e2b97aa22a07",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f83768-8e00-57f3-b26b-cd28f9baad48",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1da7db9d-3390-5a55-9cc1-d41de230158c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cee5781-74fa-56e4-8dc3-172288e4aaa4",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-aspects. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:623e41a4-d9fb-5b9d-be89-5ebfa34db8d0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec8b4310-8d6b-579f-b59c-65c5040d3961",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:654dc1ed-ccde-530d-9d92-d5bb8cee69db",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8effac6c-bed1-515a-999a-49fbbb6d48fa",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78ad7489-8512-55a3-ad4e-3601f12fe9ec",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afde236a-ee5d-5e59-a190-663ad21b694d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8816ab57-b6c4-557a-8675-0c2f67142255",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2dabd3e-3374-517d-aa42-a64879097590",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@5.3.27-tuxcare.7"
    }
  ]
}