{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b57e007e-f41c-51c2-b3f2-1c6f264c7bdf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "5.3.31-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2d42f4eb-39ce-5746-80d8-23758383c084",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aba67d18-1de7-5ee3-8662-467c7ce8f49c",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d0aa608-08ab-5819-b263-e432e10e6117",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:778b385e-d4c2-5c07-9c55-177de058450e",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c27fbbf2-eb0f-5c82-82a0-ba1c5c1b518d",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33189b73-c0a7-53d1-8f9a-f24e41fbfaaf",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5f987d3-f510-5bae-99b8-82d5365b6fdf",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf0eec9b-0551-5675-b04e-f39a9165536b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b78ac76-8e39-53d6-8f44-2ab0e6d821c8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:954e9daa-f252-5fa0-a03f-9392118bfc6f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d14d95c5-9666-547b-97ca-f785473a5ec5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0de2fed-8a77-5932-a652-83ff6d6a9523",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-tx 5.3.31-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09f3724-a35a-5594-822b-173ee4f8e2ed",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54911b27-0627-5d7d-aa09-2f01f34b003a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce1da8f-c8e3-5db9-847d-3330cfc60c25",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c16f8186-0ba4-590b-9cc8-bde695688f11",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caa7ac25-08e7-5ea9-a9e0-b28b7f1f6246",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:409946d8-c5af-5bf0-b8c6-c050bc683028",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:932e2323-d169-58f1-af59-bfe9474fe8e3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62b620b4-c396-5423-85dc-9a0b3dbb6ddb",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:839e608b-1125-5ad0-860f-0d556fc084ab",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4637909-15bf-56e1-963d-16999bf7e23a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd1b14f-3092-532e-9813-293065a4abcc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.9 of org.springframework:spring-tx. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a58834f-e04c-5790-82b9-0f1f73a4caba",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea56fae-9274-577d-9a40-226a9aee3235",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0cdbd45-228b-56b3-8f14-9fb37b507039",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc4fe385-f35e-56f3-9649-8334e799e7f2",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aec96b3-7ed1-54f2-9687-95dafdba25b8",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce0a735-7c55-59d6-a628-abbddd37fb63",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:125da13d-8627-5342-890c-1a6de981f23d",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6ce4f09-cca5-523b-aa9d-c812dbce0eda",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f7e691d-e6f1-5cfc-9281-78c7c241de02",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:790872c8-db32-513c-9796-f1530d834ad9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a2bb397-0969-5f7c-ac3b-420d67021e4e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf02ec68-a6a0-5b05-9be0-31b3232a9cd6",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cda06d6-e59a-56a7-af01-681b5bbdf90f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42ecf4e7-6311-5d10-8b37-f8b5e27cd6a2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.9 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.31-tuxcare.9"
    }
  ]
}