{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9aff764b-a39e-5948-9c7e-707cafeabb34",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "6.0.16-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:acf55f77-d937-5958-ad30-45792117eebf",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5ec83b5-e145-557e-88ce-ab6480160260",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4539112c-7736-5d33-951e-7544ae42d543",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df719ead-ae48-563e-9a8e-3f9ee3e6b191",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ec3f06-0392-5054-b896-87328a862c36",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df6f820d-e594-5713-8e0f-b5ea82e66fbc",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdbdcb7-7e72-5512-a23d-8d9225f5210a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd5dfa1b-cf30-5e2d-835a-1c6ccf91b27f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:112ebec2-7bc8-55ca-b8c1-21291f373371",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:021ab7b5-8147-58de-a8ea-bfa769b657c7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:848015b8-4091-5701-a67c-2456114f0108",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dee75bc8-c730-5ce8-a53b-84ba2a3a2bad",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e9ff799-6579-5381-ba38-0b885a314ab2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0b8fa05-2b19-5f69-928a-500180322eed",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.0.16-tuxcare.1 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@6.0.16-tuxcare.1"
    }
  ]
}