{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e5b6c5f3-b9ca-550b-8351-ddb6b1e7cb0d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.30-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c4373660-124d-557f-8079-8143863dfe71",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9ff875-f1f3-5703-a945-37ab67b9321e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e21ae26-0d15-51e7-9c86-eb982a51475c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb72bdb6-8a55-5c02-90dc-d451b4d1ded0",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2506d25-dd79-5518-bbf2-8eeedda360c2",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a066ab4b-eb96-5960-a9d0-9dbd6530fc85",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab21cab4-a8ef-5e10-a7ba-84a078884add",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e1cecf5-6e7f-530c-bbb8-1250af95d873",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60865370-abac-5f1c-a4cb-030a248c204c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06bb3e2d-d29f-5171-83cf-88a5435d2418",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91f08af-bd9e-5c5f-9557-728d29c5b718",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1389d84-d52f-5fdc-95a7-74a727c70a60",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b222e88-20e1-5b32-8db1-ac0cb632a913",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6bbf93b-e80a-514d-af7b-b6f25eec50bf",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:968f06cd-b26f-5936-bce6-956080bd890e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03041a03-d6af-55a1-89a9-5da412e3b6c8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e27857a-cea5-5242-9dbe-2bc2e84d6acd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a9107cc-fac0-59f3-92fb-bee4fb457124",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12ddcc4a-60c2-5fad-b885-eb9966f0541e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b71bea92-74ed-51c2-bd05-1d687ecfa0df",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a82c4507-a87d-5fe7-b570-b9c84934f075",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21e95a88-e0ae-5542-82e4-185bc5567d6a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.1 of org.springframework:spring-beans. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fae855d7-ac21-5975-a89e-3b9ae182cb77",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a9cbf99-d5c5-502b-9879-a505776e7158",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:354f7383-3f3a-5982-8381-612ec6909872",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ef9f970-ac45-54c4-b04b-dffc87f96240",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bd0af79-6191-5e9f-b9d9-8a84557ac6c9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e065c9ac-5ffc-5854-97dd-0dc4a4fdb826",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b1eb65-e0b4-5a72-b734-1a39962e9ef9",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c01d25a1-0f65-578e-bfa6-81e8cc47565a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab70f870-2e2f-52d8-a763-431b936c89fb",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c2b37ef-75aa-52bc-bafb-c4fcaf4e0674",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:209d6cc9-468c-53c0-9ba3-6a87e327884f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:132d618e-0e8a-5508-8a4a-5639dbde3359",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fbcd90c-ef24-547d-a7ba-39c0795a70f8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c12d3ad0-92ac-5560-9a22-e0143a8a46bb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.1"
    }
  ]
}