{
  "@id": "urn:uuid:927af32f-2ba6-4014-abe4-1e641761aac2",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-28T15:55:53.676660+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-jdbc-distribution@2.1.8-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-jdbc-distribution@2.1.8-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-28T15:55:53.676660+00:00",
      "status_notes": "Vulnerability CVE-2026-41697 does not affect version 2.1.8-tuxcare.1 of org.springframework.data:spring-data-jdbc-distribution. not_affected \u2014 Version 2.1.8 is not affected by CVE-2026-41697. The vulnerability specifically concerns Query By Example (QBE) with StringMatcher functionality, which was introduced in version 2.2.0-M5 (March 2021) and does not exist in the 2.1.x branch. The target version lacks the vulnerable RelationalExampleMapper class entirely. While version 2.1.8 does support similar LIKE pattern queries through query d...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41697"
      },
      "impact_statement": "not_affected \u2014 Version 2.1.8 is not affected by CVE-2026-41697. The vulnerability specifically concerns Query By Example (QBE) with StringMatcher functionality, which was introduced in version 2.2.0-M5 (March 2021) and does not exist in the 2.1.x branch. The target version lacks the vulnerable RelationalExampleMapper class entirely. While version 2.1.8 does support similar LIKE pattern queries through query d..."
    }
  ]
}
