{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0b2ea53f-2fbb-5869-9d56-9f03e6461a50",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.31-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:39a7de69-5933-54eb-8d9b-d5bb5511fcbc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395361f2-3d5b-5631-a58a-0dec55266a58",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69c64dd9-d0ce-5e1e-a6c9-488864853d40",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22f058d6-b25b-5ea4-a864-ff4aa2674655",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7499289d-caeb-5e4f-9073-40364032e87e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c933c8-aff9-594b-8e6c-2d98fe4ecbc4",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f929bfb-7917-5658-a074-4816222a79f4",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86f2b520-eaee-5441-9c28-e7284ad88287",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:460e89d4-4de6-5fc9-95b8-91c677eae604",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf7ef945-785f-52ff-83db-f3acce69b7fe",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d0d638-46df-550e-a02d-62a66011ae14",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:741f1146-b653-5a94-8513-31506ccf4451",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.31-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8500ec67-7e4b-54c3-87c2-13278de81fa7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32871668-3125-5122-ab92-2106382ddb4b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81af2d8-6e4b-54c9-950d-1424235b4815",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1074c858-bbdc-5eac-bdfb-9f07acf29292",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9d728a3-482e-511d-a36e-f5060ae8c60d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd30db88-5d32-5817-a4cd-eedff11cd1d9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8213bd5c-942a-54bc-bc60-3690d4e51dfb",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca222477-ee19-56ae-a596-20a8c2b87446",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66fda543-7b8c-520a-97ec-fc83773bbc5d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf86ff5f-b050-57ab-8e29-6412497468a5",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72b743d7-8395-58a1-b978-52f7c5986709",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.6 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f748726e-8e1e-536b-b07d-d6ca9c6e014b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f22c113-d805-5bac-84b9-9adaf5f592e9",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c81fa47d-8088-5400-a6c6-5e271a4d2bde",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:239bcadf-7d99-5dcc-bd31-551664606022",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d127d63-4bf1-517e-bb98-6b3013f6821d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baa1360b-ee1b-53bc-871b-918464294685",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb88c960-66f8-593a-a59f-981e8ac289a2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfdecc6a-c897-568e-a4a1-d44688442325",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c17c66b0-3680-5e6e-b76c-073477a8c907",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4120eda-b6fe-5b7f-b659-be83bfdec414",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1bf630e-6cfc-558c-9ee9-99c2edab6b65",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c473e2f-dc9e-5a3b-bbf5-c698de695a73",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aae319f-9761-5186-be36-198b7b4fc7fe",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6afd8a90-ce86-543c-8c09-d0b2804328df",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.6 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.6"
    }
  ]
}