{
  "@id": "urn:uuid:5d2aef82-78d9-440d-acbf-cd7f3f990bdf",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-jdbc@2.1.9-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-jdbc@2.1.9-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41697 does not affect version 2.1.9-tuxcare.2 of org.springframework.data:spring-data-jdbc. not_affected \u2014 Spring Data Relational version 2.1.9 does not contain the Query By Example (QBE) feature, which was introduced in version 2.2. CVE-2026-41697 specifically affects the RelationalExampleMapper class used for QBE with StringMatcher (STARTING, ENDING, CONTAINING). Since this class and the entire QBE functionality are absent from version 2.1.9, the vulnerability cannot manifest. The feature was adde...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41697"
      },
      "impact_statement": "not_affected \u2014 Spring Data Relational version 2.1.9 does not contain the Query By Example (QBE) feature, which was introduced in version 2.2. CVE-2026-41697 specifically affects the RelationalExampleMapper class used for QBE with StringMatcher (STARTING, ENDING, CONTAINING). Since this class and the entire QBE functionality are absent from version 2.1.9, the vulnerability cannot manifest. The feature was adde..."
    }
  ]
}
