{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2a645fef-1d16-567e-92d3-ceca17143106",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.31-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9a406db9-10ba-5d75-a993-34f7ee0d4f00",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd5d516-2e7b-5cf1-99bd-ac99050cceb0",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d2ddeb-92ea-50e0-b2df-db13f49de948",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046acb8b-7deb-50c6-bd9b-096ba42a343b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b0c34fc-fdf7-5ff9-9663-4329e2116440",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b81e1f74-201d-5adf-94ae-11187c534837",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:598290b3-4432-548d-bd36-527bd3c8f275",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:121cf1c2-c499-563b-8498-136a9ad10b25",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:497ab94e-5ac9-538c-9136-7f6cef752275",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94dbde94-b19b-5356-9f06-066c66026ff7",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d5e856-24e7-573e-822e-3e46967a6785",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba5b1a14-1891-5b76-bb76-88e3b458b1f1",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.31-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0508906c-45de-5943-abab-1f88d4222ecb",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eaeb22e-ea22-53c2-b81b-bc5f03593ece",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b902d14-f648-5842-ad86-3b5ef0066dbd",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1df879-038d-5291-967d-523f19e85042",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:121d4df0-45d0-5ad8-a41f-5fc3ff84c6d3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61c12fe8-95d2-5ba5-8cf1-fd20c8ce13f4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57e52d5a-f454-5622-bc8c-54c268e202e2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b81acfaa-ed98-5cf1-bf5e-fd44c2e0001f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eecb4d49-4574-5533-9436-6bad70d80914",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07f01c7-2894-57a8-b993-2c2d84a631f8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:344d3b6c-4fd2-562f-9149-65b8dacf8434",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.8 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b904c49-f690-520d-8802-8867ff480431",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05d3c583-06a4-593d-9f77-810ba41d776a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16f728df-3e79-51f2-bb3a-5ac232a1d2fb",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b5302e5-2173-5d10-8798-4350c5ac47bd",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03f5901-81a8-5963-b1f9-20ad6f866948",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e7183ae-d370-524e-bc69-09bdf3528e03",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b9a5e26-ae75-5938-ada7-82315725657e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68004e0e-1c63-56d3-b7e6-5896fdab9d96",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87e2f14d-3869-5fac-a391-62eef71ccbef",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86ffce40-2f01-5eb1-a0f7-3dee4991c978",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7582e3e6-0e6b-56d8-b154-d32900f79953",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0f908f0-6724-5c62-90a3-0923c8b77e21",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca5cc37-7ae2-5a07-ad05-f24a749d6846",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79d0638-1514-5b6a-8851-10ca0e914580",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.8"
    }
  ]
}