{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5e2cefcc-0599-587f-ae68-1ebc2927d595",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "4.3.30.RELEASE-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8a93d240-46b6-538f-9f41-b39fed99b476",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac12836-e9c1-54ea-af1f-ce8dfa31dbfa",
      "id": "CVE-2020-5397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ea9627-421a-5815-b716-bd2cb8a3f720",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f375a848-d10e-5062-bbae-b1f1ab42a56b",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285e0cb4-29db-5204-b15d-bb8c7b4962de",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2eb6074-b196-5a8b-a679-213561338744",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:289340b0-eea9-5aae-aa14-2ef8ea1dd22c",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b982e9f5-a85e-571b-8c8d-4ad549aa9dca",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8beb8a55-9ddb-5058-af90-199f122e9105",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b670fcf7-a531-5865-b3c0-eed4fd6baf68",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f836ef8c-ed1b-56fd-a678-f86ce1d1e351",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:848115a9-befc-5c26-a779-6877a67f3cc7",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f3f066-b96c-5e80-84e9-a10de3f7158f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ad661e-57b0-5e76-9af1-1303db424033",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fd3418c-ab2f-5f30-a292-8d4f65a83f4d",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6cdb355-de66-543b-813d-7ef9e5042f11",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a35a65d-0a3f-5f0b-bea4-03ff25cfb938",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3187a474-9417-5412-af95-235958cbddad",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7baad0-d09e-5f2c-9716-1aa8a74800d3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9ae0c7a-a20c-5478-af3f-f72546ff6a08",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3029737-c9e6-5357-9992-9b0dcda9d050",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b85dfc02-87d1-594c-8e2f-b1d85ed48a1f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0ad6708-bb8b-57fa-86c4-2503b803bba9",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67901c61-0201-520f-9c6a-1f5138b80729",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d25ca258-477b-5218-9fcb-7304619e4e0f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e830ca-919f-51ea-b5f6-832d4312bea0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:016e3005-a08c-5729-91e5-6bf74ddf63e3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee12a3a-3f96-5493-b10d-2b472188f87d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395819dd-5376-5c7c-814b-712ebd1a7005",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d16975e-2550-50cc-bccc-4ce4243351d8",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749b3fcf-bf20-599b-8799-df785cfc57ac",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70226a9d-82a3-502b-a62d-be70f6fe33e5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d541681-189c-5bce-a4c4-21be92d366a5",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3196561a-309c-5316-b95a-b4f7f67af04f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c5c53dc-c3c2-5730-8339-5e03ecd96b89",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:732ac0ca-2a0f-51a6-9fc3-4ed6da4d324a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80a0c67-bb4a-5896-b281-f470bbb2b260",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4221018-c1e6-502b-997a-0d6fe797041b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4c9edac-8fe7-50be-823f-9a57c841f8db",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feda8a1c-1e30-5b34-a7ee-3e81eca2b04d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc8335c8-472a-5dbc-8e2f-7ca1ddf08314",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa17c239-bd75-50da-bce9-b278a3d6ea9a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.5"
    }
  ]
}