{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:264ff3b4-5496-5dda-9f79-f9c46bb15f87",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.39-tuxcare.16",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1903c2de-4650-5b9e-8545-93bb5ef88d9b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44175034-d85e-5448-b8d3-1bf39d16ae37",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.16 of org.springframework:spring-beans. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51c937dd-678d-515b-8515-cecfc75e243c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c84649-1003-55ff-a7dd-3bbada07d64a",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd33a7eb-221d-54f4-abeb-928ab45117c6",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63a6e479-74c5-57ce-949f-6bc95f9a8591",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c551b9c-4dfa-56e3-96c0-a5e2af5396df",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8ca1819-535f-52bc-8bd2-eaed2a7dd89f",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.39-tuxcare.16."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c335cbf-566c-513b-b56e-742fb54a12d1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:438ccd33-5e64-50b8-bd51-ea2c6ade8630",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b67eb5-8f35-5f15-b233-e0e23dac7194",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a09758d-6235-5a0c-9de7-10d398a2b553",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dae2e56c-06d0-5396-93ff-d09fe75081b7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee36d1b-9fe0-5954-8001-3a5191b76e60",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41826ae7-5e02-56c2-bc6c-cb512bcf3fc8",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7abbbd80-d12d-5e09-beb2-9af5db903659",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36baf366-acb2-55b0-96e8-a04d33427825",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8691c84-7477-515d-8471-bcdb53f52110",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c88fd45-8ae6-59fc-b353-0f4293374ebe",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.16 of org.springframework:spring-beans. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ccc564b-334a-53be-85fa-792fda1cf690",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92dafd8a-1165-5d17-86cd-73d637e770ae",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730d86bf-4531-58ea-a2d8-f0d0b2ce63fe",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:900c3fd0-21b3-5d20-bc9a-d4e804ea6d10",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf6bb5fd-368a-5371-acd2-a83f552e5fbe",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f695a037-fb5c-5741-ad69-926f99868ed9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2310179-5c1a-55ce-bc45-82bf13067008",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe290cc-f422-5314-a768-7cc0c78452f9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27b9465f-0e68-5404-b2c8-f445f8c42b6d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:238090e0-b746-5571-976d-886be2147e92",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2854555f-ac48-5581-9f11-277ecf1f7d44",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b97ed1f-ce35-534c-88e0-58d0fa9bd63f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945222f3-055a-5507-b04a-2b00a1284c5e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7136c13-4c60-50dd-accd-097dfd44c221",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.16"
    }
  ]
}