{
  "@id": "urn:uuid:8ce228a7-d747-4b45-a479-863e7faffaa2",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-28T16:48:00.287697+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-28T16:48:00.287697+00:00",
      "status_notes": "Vulnerability CVE-2026-41695 affects version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons.",
      "vulnerability": {
        "name": "CVE-2026-41695"
      },
      "action_statement": "Vulnerability CVE-2026-41695 affects version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-28T16:48:00.287697+00:00",
      "status_notes": "Vulnerability CVE-2026-41711 affects version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons.",
      "vulnerability": {
        "name": "CVE-2026-41711"
      },
      "action_statement": "Vulnerability CVE-2026-41711 affects version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-28T16:48:00.287697+00:00",
      "status_notes": "Vulnerability CVE-2026-41716 does not affect version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons. Target version 3.5.12 is NOT AFFECTED by CVE-2026-41716. The vulnerability (unbounded cache growth allowing heap exhaustion) was fixed by upstream vendor (Broadcom/Spring) in four commits that are present in the shipped version: a4f893b66 (ConcurrentLruCache in PersistentPropertyPathFactory with limit 512), e33b68517 (MapDataBinder collection limit 1024), c3b2abf29 (max traversal depth 1000), and 239860738 (LRU cache for type alias with limit 1024). All vulnerable unbounded caches have been replaced with size-bounded LRU caches. The fixes were authored by Christoph Strobl (christoph.strobl@broadcom.com), not TuxCare, so this is an upstream vendor fix already in the shipped version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41716"
      },
      "impact_statement": "Target version 3.5.12 is NOT AFFECTED by CVE-2026-41716. The vulnerability (unbounded cache growth allowing heap exhaustion) was fixed by upstream vendor (Broadcom/Spring) in four commits that are present in the shipped version: a4f893b66 (ConcurrentLruCache in PersistentPropertyPathFactory with limit 512), e33b68517 (MapDataBinder collection limit 1024), c3b2abf29 (max traversal depth 1000), and 239860738 (LRU cache for type alias with limit 1024). All vulnerable unbounded caches have been replaced with size-bounded LRU caches. The fixes were authored by Christoph Strobl (christoph.strobl@broadcom.com), not TuxCare, so this is an upstream vendor fix already in the shipped version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-commons@3.5.12-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-28T16:48:00.287697+00:00",
      "status_notes": "Vulnerability CVE-2026-41721 affects version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons.",
      "vulnerability": {
        "name": "CVE-2026-41721"
      },
      "action_statement": "Vulnerability CVE-2026-41721 affects version 3.5.12-tuxcare.1 of org.springframework.data:spring-data-commons."
    }
  ]
}
