{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e6030cc0-ca6c-5be7-bb29-8a39fc5a9e75",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.37-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c0ab96f1-e1f7-540b-b296-d936db5749ea",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b39c44e8-c6e4-59b5-beca-574b7d87ccde",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c56568a-0827-534d-b5f7-d0bb4f344fe4",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e17c8817-6dcf-5ae9-8454-e7d732121d07",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4116ce6-d8d0-5472-a59f-6f693f4c570b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5529e39-3ad1-51de-b124-a3976f2df155",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba377ff8-ef3a-5bd7-86b3-c1d85a44666c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb095b53-e9f5-518f-83ff-486228873814",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9120f8a6-c9ef-57bd-86fa-62c9ea77f584",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7ef7222-110c-5a85-ab4f-9f16aaa3999d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21b789d9-9e6f-57b8-b89e-b724c77d783e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d674758-3856-591e-9e0b-217f34977225",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f198013b-838f-53d3-87b0-0aca41db40f7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c83c1ea8-67d1-50fc-b181-a732b3f7b389",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efa212af-e5f1-56bd-a9af-453b16856b20",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:614c34f4-6d5f-5906-9124-fc87d5ea48b7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3d87c0e-fa51-5204-8970-eb7a9e861199",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427cb16b-a00e-5e79-98e6-79bd088444a9",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d50cbd1-203c-509e-a049-8c91867d6546",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30266a6d-e044-5cac-9a5b-2ce380ec4362",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23cd15bf-1f4b-546f-9b17-9325605c5105",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f2ca7be-6880-533a-929a-c868524cebe9",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85f784fe-b83c-501a-9ed4-a227a7e61301",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96ea6685-79c0-518c-beee-7463e936add3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:093ed587-da42-5b25-8cb8-047c2dcc236e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d329b9-5920-5673-a4e4-be3d49eaeb8c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91dd091d-8fc3-551d-8d62-bcb0f2feebc3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6fbba68-b75b-5647-8df7-93202c060f46",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-aop. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8f1ce3f-9439-5efb-bf3f-0e6c6341e2e3",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6772c72c-917b-50b4-8e14-ac8adf39eb56",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa0e9280-df84-518a-b0e8-79dad01ed3fb",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55216d05-2845-572e-a498-de972e758ac4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a840b20-a670-5862-8b34-394148d330a1",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-aop. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23bc4765-45c2-51c7-a055-baad99f71d81",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0a1b510-32a5-5b49-9f81-da7d4d2b1ca5",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e5fea93-c666-528f-a48d-a1700012bf5c",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acd1ef80-8d9c-5b29-aeab-c19d02fee718",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c99b888c-1a12-55e3-9fb7-d329dc7f3562",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b77248-3b1a-5842-bca2-a0904858cc60",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf8e63d-d849-5be9-af67-c032742efd61",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04ebdf21-3fec-50cd-bf15-ef4dbf24ad7a",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cf3c29d-5e14-59a8-b03b-22de86c41895",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e7c5448-2552-53a2-835b-a59144770c03",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e38f779-35e0-5043-ae61-768040d444f4",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94b4fe3-f049-55a6-b217-212a0e6b7923",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7bf6d6d-2dda-5028-9184-00bea385cf5e",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26532896-9d8e-53d1-b393-56f505bc36b6",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.10 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.37-tuxcare.10"
    }
  ]
}