{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:62184b96-764d-56ef-b027-0a87c9214363",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.37-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b63ace62-b676-50a0-ac02-d2131e16b063",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114958e5-ae65-5e9a-b471-9e62f33b8c1c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58ab2c81-e1ed-54ea-8aa7-5ec5df2c3a3f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66f0ed07-6184-5b00-8a30-aa51c57d8e58",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9c0a6b1-34ab-5892-9f71-40365ed64ae6",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b1c41a-d2ec-518f-9b78-7af298065d4f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bff190f-194b-58b6-b30e-8490de1cc880",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca1d97f4-4b12-5841-9cfb-eb224fbabfbe",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d700cf-cb4a-58bd-be1a-30071eb41281",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3ae972f-7df5-540c-9028-254f768230bc",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:415ec666-e738-5167-97f8-fcb0e6ee206b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7eaa46b-358f-5c08-96f1-ddcec7d01796",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe904912-59ba-56f1-96b3-116edde3d803",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8da958a-572f-5744-93ca-7dd38546a74c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89eed827-14da-5b23-9ad5-3ffd31ce9cf6",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4372b7c8-2633-582f-81ab-c3b947b4140a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e15198d1-9eb1-5f90-9c12-376ac71652b6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f54a516-4d5c-5f38-93fb-152e901a91e6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0db470d4-3c7e-5b29-816c-c9c9ba736e47",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-tx. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c823941a-b05a-5de6-b6df-4e57b1c65b7b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef26fade-ccba-5023-b2ec-619f0187e496",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d211f27-20b4-5c1c-b7de-337fc4e37e60",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baa2e049-b69f-5217-a140-2fa0330f4dfa",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f2d5fa-d7b0-5ea4-9a81-8dc5b5829455",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c49da600-e596-55f7-9d7b-9a27d61f6d73",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1c95ad7-9aac-538e-951b-6d830dd4de43",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:341c205c-2572-58ba-8c50-2b689cfe5323",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7954964a-e891-5066-a576-9b3c7efb3c4c",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-tx. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d403ed-1aaa-576f-81ee-763e76e8e6d2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd0e2696-dd16-5f69-afca-167f6caaec83",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca1a097-c9e6-5e64-af33-f4480bd0ea61",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81c22c9c-c89e-5bf7-bd98-66f66e2252b1",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9058594-5b8a-5319-9ccf-361671664290",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfca7d2f-3824-5e51-be85-b841690c38dd",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.9"
    }
  ]
}