{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4b4bf8ab-9a58-5467-8478-ebcb8e29c219",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "4.2.9.RELEASE-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6761dc84-07e5-5bfa-b408-b0c521d7a5d1",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aaa60db-300f-5ff0-b7df-95035726f845",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6cbb0b8-100c-500c-8694-0d29bcfc8a88",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5b937ae-ce07-55e2-a93e-d15e47c82955",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c882c69-7c70-5268-a514-6d4e4c0eeaa8",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2c69843-b4ac-5510-b7e8-e6bd39b801d7",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2f911a7-09c5-5e0a-9e51-dcffca19beda",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:467dcff3-a400-55f7-b06b-ec332952e5bf",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f718613-83ad-5b8c-b93d-3eabdf5964dd",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b290f289-c6a5-5f65-80d0-d8b324c96857",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca4e359f-8cf0-5f33-9631-b8954cbe0401",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d80efbfa-2111-515f-aa0e-f41bfc1b297b",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03790a32-07d0-51e0-8462-b955d4d1218f",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9147efae-a3a2-5090-8ff6-5cd1bc10e522",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0440a1a1-8ffa-5b01-b75f-dc8110867ee8",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6026b8ba-92e0-5a5a-8222-4e76d4f53785",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d49da5-acdf-5e84-a6a6-fd3e478b541d",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22fb9cdd-491f-52f4-bc33-4ff0584aee1d",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa79a914-4f67-5fb1-9511-114eadce2b65",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15bb3758-217d-5b63-9675-d4eaff965b71",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02a13a4b-91e0-5879-a1cd-0a6101b0e1eb",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f028eee-8b52-54ca-af4a-6a4589b5bca5",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1e6025-6814-5ce1-bd80-ba847035119e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e25193f-8217-5cfd-af8e-9e49475f3665",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d63097-4284-5c53-82e2-67b61baf70ea",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b19e1c26-57e3-5689-9cd7-b4c4a0f9b0b7",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b11842-a690-5fe4-ad65-b282a620e793",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be02f1ef-fc94-5002-9f01-1359e9bc96d6",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f288fba4-4713-5bf5-ab4e-fbb560758708",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d3a0d0-7943-5382-b250-20f44c72698e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39880f98-9679-5365-9b90-26f7a0c94f6f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08c0e80e-b7aa-5006-9e49-143652274e27",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e01d863a-339f-5919-ba8d-9b0c477c04c6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a8919f-301d-503f-978f-68f788899414",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31ef9821-ba34-55c3-9ea3-7fc0c4043ade",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc93111-b949-5861-8a2e-2e9938b74574",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fa1aa15-078f-559f-81c2-67d09bed1eee",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:158c7563-c7ba-55cb-99c2-bd48e8f675d5",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16781399-25c1-5710-85be-32bcde0e869e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36966fcb-2b45-50f6-b743-4757967539c3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22389bc3-e7cb-5232-a056-a29fb961a8ac",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6ca6bfc-cbf9-577f-8bf3-486ae4eb9cc8",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c124686-5a46-5e5f-87b7-5aed6ae9b6c7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f47df57a-807a-597f-9927-e546a8a2fabc",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbde242f-1558-598e-9221-e213547458bb",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d44516a4-d363-5713-bd8a-908f6ff7735c",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5286cb64-a334-58a4-b771-2d7c6c80ea36",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.8"
    }
  ]
}