{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e306db74-cde4-541d-a163-2e86fffc37dd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "5.3.30-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:145477a1-e635-5663-a4e2-b6d9d0ef2c91",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17a39210-b5ba-5ff7-8f39-0dbee6707bcd",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b89cda5b-58da-5b7c-89c9-b777e532fe57",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e6b82f-7686-5a66-a3c6-f5cdee819ef4",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb5a543-79ab-5db7-a2c5-36551cd631ef",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74206ff9-937c-5e7d-8b77-20f14432ba78",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26bf197a-52ed-59df-a15a-1489533e6092",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3217be08-5837-55db-b1bf-4df4172f1065",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4b81487-871f-5ba6-8a80-2eb9d8917d6c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8cd2350-5421-57c8-9f79-bd26b2f3818a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15c4d6c9-fb64-5dcf-9170-4666511a165c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:629ec2f9-0998-5e57-b6a8-4f5d73206e21",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c188ac2b-cf04-5cbb-8c1c-5875ffcde271",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef151be-04d5-5c25-a324-7c4f994fead8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adad99b-135e-5fe9-99a8-ac4f2e1bb8bc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5bffdd4-cfcf-502a-a26b-26c7f1b77391",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acc98e29-52c6-5dd8-823d-17339dab95f0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff462eb0-b7d7-510e-a8cc-35fe62718f43",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a581f2-d3e1-5649-a4c5-de0cb175b293",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1906fccf-a868-5a76-a635-e2d5952d6037",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc31bfd7-bfe2-5d30-9118-8e367f377d7c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90542c33-dafb-5212-be05-77483853bce5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.6 of org.springframework:spring-oxm. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2246097-723a-57a6-8c9e-9dce1435fb33",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ba6631-b889-50ae-9876-e1941fd2496f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af615891-cb90-58ce-b759-3da5adea096e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8676585-a153-563f-a4bf-db99b89265c8",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696cf052-57cc-556f-b3bc-b8cb7b6a61e5",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a5b3bb0-933e-527d-8c06-61347255b7a9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53098d3c-f9e8-5b5c-962f-3762e5c4447d",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4b0ee5c-e909-5958-a58f-44f4b23b1fcc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07400cb5-e5db-5e4f-a7ec-29c3750cff45",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9650136e-acb0-52f0-9efd-7a13c0a07c33",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb387d48-caed-53eb-b6af-94bc64bb6c89",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d37a8792-5ab3-5507-a3d2-251a701805fe",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb13d9a-19a0-5025-84eb-3cce5c87991e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:510375f2-13d9-540f-8c75-421a2c98a5b6",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:102d6d11-3110-50c1-81bc-bca98bfe8d5a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.30-tuxcare.6"
    }
  ]
}