{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3f5433d4-08f0-5b12-9d11-cdc0554e71bf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "5.3.37-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d945478e-878f-5f80-94ef-98793c77cd67",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d76af70-714b-5ec4-bdc1-0236cd796dcc",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e97a1de7-47f2-5d6e-a8f4-3a37abaa3545",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd368099-c37c-5b53-8b95-ddb73d966479",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13434ddb-039a-5962-9efd-008975996a4f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:333b386c-8052-5996-a970-4f0dfafa9c1a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44848b72-2c23-546e-8b3a-9c2745223be4",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94268ae8-0553-5053-8d82-5371cbacad1f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a709a7fa-4124-5a36-baec-ccafc5c398b1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c339b1c5-8f10-5ae7-8737-945e56afeb63",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a247db55-f38d-5d50-b25e-edccd1777dd2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b43c758-7067-5a95-8044-b9c75df55ca0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc45441f-22df-52eb-b8ce-02ea2b65e1d2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cce066b-9bb2-5cfb-8b06-985abe55820e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0271298-5b6b-53be-83f8-65a0e74351d8",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d0f66f3-9118-5f09-9ce3-19736e8bd77f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4790e01a-b4b4-5310-bab8-dd639a0561e4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45ddc396-c308-5118-8a81-31dc2b2d50c6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8285adcb-74d6-5ce9-8915-5459f69ee652",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd21f92d-d688-5a83-9e7f-6a9a4e47412a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:324686fb-0f7d-5d77-a5e0-bc65943704ea",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:706f78c4-c2d5-56ec-b938-b38c0cddae20",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23ff40b6-4a89-568c-97b5-bb7d4b833f8d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29b2e01-eaa0-590a-aaab-e9dc85ea305f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc610a69-78a4-5c6b-b0e7-c3e8e97ae540",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:305c558b-bb80-57f5-9358-9b135535cee5",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:740bcf36-7993-5606-b1f2-c00ac1a1ed0c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195fdde3-2175-59e0-93af-5d3380505064",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-messaging. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a9c842b-3629-5474-b902-27405a8a3164",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9178bc-a377-5820-95f8-7387e31c0253",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41fdc18d-2678-59ba-b2ef-98c06035bbee",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f09736-db93-5c91-bf17-735e1bec97ef",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb6ae35-7994-5254-9382-d34f96e0ec6e",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-messaging. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945f6070-b5e6-52b4-9623-811cfe60075e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8372014-b6c2-5423-bb36-e902d1cb652f",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31d00258-f345-5b8a-9e37-dddbc012ab54",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:762ba3cf-1a16-51c7-9708-4284739206da",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28bd2a39-1640-53ff-a1d1-1ead6fa474d6",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c54ebe69-455b-5cda-8eef-a49f1d571bd4",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:908c40a0-35fb-5e83-b424-dfa4b9f6e00e",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdef7a3-7480-5194-aabc-ab215b52556d",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:211aba30-4465-5b23-9a64-b2cc7f1a6e82",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1af9d00a-0d29-51fd-b6ef-439ff0d7de56",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9cf07a-56b7-5d4b-a49a-bb10281dc2ee",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c6ccac5-fab7-5aa9-9a69-91e6aa27a746",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:184972a5-2312-56da-b1df-c9c81175dea7",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bd64076-f5c4-57e9-af15-faa45b787a25",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.3 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.3.37-tuxcare.3"
    }
  ]
}