{
  "@id": "urn:uuid:7e781175-2ed0-46a9-952d-55822a69ebf5",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T13:29:00.171799+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-jdbc@1.0.10.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-jdbc@1.0.10.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-29T13:29:00.171799+00:00",
      "status_notes": "Vulnerability CVE-2026-41697 does not affect version 1.0.10.RELEASE-tuxcare.1 of org.springframework.data:spring-data-jdbc. not_affected \u2014 Spring Data JDBC version 1.0.10.RELEASE predates the Query By Example (QBE) feature entirely. The vulnerable code components (RelationalExampleMapper class, Escaper class, and QBE string matcher functionality) do not exist in this version. The CVE affects versions that include QBE support with STARTING/ENDING/CONTAINING string matchers, which was introduced in later releases (confirmed present ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41697"
      },
      "impact_statement": "not_affected \u2014 Spring Data JDBC version 1.0.10.RELEASE predates the Query By Example (QBE) feature entirely. The vulnerable code components (RelationalExampleMapper class, Escaper class, and QBE string matcher functionality) do not exist in this version. The CVE affects versions that include QBE support with STARTING/ENDING/CONTAINING string matchers, which was introduced in later releases (confirmed present ..."
    }
  ]
}
