{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:046a3cfe-2f14-58c8-ac9e-fbc11077989d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.3.37-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:36f19bf6-abde-5b03-87f5-e306a33c3444",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e905f383-6ac8-5e31-a2a4-a253ec8e174c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0710b7f7-6d16-5052-af2d-86696066b497",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7367b70c-6990-5c68-9242-a6a3b28d8a4f",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cc64618-490d-5a4b-ba38-66d13aad3874",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff689c64-3bd2-53a0-835f-027898e46426",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94e963ce-71ec-54bf-a736-96e44e92eede",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:622dd6bf-9f72-5f6c-abbb-d689ce434962",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2de33eec-f716-52d4-bc2e-03e397d15b47",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:964dfd3c-b1d7-5402-a7eb-e87cb09cec0a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d7abe1f-21f5-52bc-ab67-6053ebf1d212",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e6cba7-fc55-5c41-bad0-b6729a032246",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed7d468b-643c-56d9-a0fd-79e57237edc4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfefca2a-50e9-5dab-92d6-66c67ae50871",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11b41e72-d117-5d3d-9b2b-034f7ee290a2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e280b75d-c035-5ca0-9d33-94d27144c912",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddf31872-f48d-59b8-9933-e76cfe7b2876",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12558246-02f9-55c0-9b58-08f27b943dce",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea4b69e5-d862-57f5-baf1-85da29e46bb0",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.8 of org.springframework:spring-jcl. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9427534-c5f3-5c53-97f0-6a9edfbb0e6e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab10e1d-91c9-5b24-8af3-f2cb8dbc01a1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c66297c6-8342-5196-8e0d-25d4c08ffb58",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36c60579-9397-56f3-a90c-46ecb74fd7ae",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e25e42cb-133e-5bf1-99a7-c361dad82998",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6deda4-5bfa-5186-b7d0-fd90e78fe1c9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:300d5a1e-8696-5263-9d3f-38ef2d0f37c8",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177f7312-0e04-5df2-b587-4b2385cc652a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7db650a5-7151-5d9d-aaf8-718e244ed7e3",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.8 of org.springframework:spring-jcl. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a26eafa-6bef-5506-9160-61711c59fdf0",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599fd176-f461-58db-92d2-0249c50fe3e6",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193b4217-e62b-5d8e-9747-09454fc5eed2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95df2a9-6d65-5939-82a1-b0ce4b7332f6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3beb68b-224e-5807-9135-951f1d67d86a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.8"
    }
  ]
}