{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d23bb9f-e546-5b82-ade4-acc68f1c25ce",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.29-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:892be10f-66a9-533a-9841-416859baf859",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7d4fa85-0434-5e69-9667-ffdedcdd81e6",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:180f7e0d-7f24-593f-bc6a-a2990521bdd7",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c03977-6941-5238-be91-a37f7ac88d95",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4823d4e4-5bf4-52da-851f-b576a343f75d",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8cc35b1-76a2-5a83-9649-d5b3a55a26a4",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9aac75b-f5b5-5fcb-9ce6-cf511da690b9",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e41edc64-364d-53d0-b8f9-f292eaeffbc3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9651430a-855a-5a7f-aa6c-d0d76d6c56b3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d6f8dd1-a64a-5b44-9c62-abcfb21e7b53",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d2524ae-e8b8-5c13-90ef-be383a4ff7f0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:303e2d90-efa0-5310-99be-1a37053e4ba0",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.29-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25c0d90a-07fd-5b89-8640-864e47a02d90",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31e1fc47-702c-5971-a3f6-a8420e37d970",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b0b9c86-7634-5952-9b86-19f24a0ddbf0",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f6493f-abc6-5387-b03f-cd2551a12fc6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3132df9e-3536-5650-9610-b7eb145e70c3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff4761b-6468-5c4c-b007-067b34a25951",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5353a0f3-8db2-590d-acb1-df4d1b042865",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a4c05d5-ad8c-5324-bf00-99cac0aea3df",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e43b3f-7e0c-503c-93c6-9bb1cac2a515",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dc72c25-0074-5eff-9ea7-3c4419d44f91",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:333018be-df67-58f2-84f4-cac5b800237d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f7109f0-e5c8-58a1-bdbd-87f536fb5f8f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57909ddf-b08d-582e-ae6f-74f9c524d5b5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0ac6e9f-e4aa-5344-a382-1ce1db5344c3",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2501647f-c036-5f8b-bf31-0408b87aa70e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c45b178d-e336-5383-b369-03001e6affe3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddeb2a55-a7e9-52f8-bc53-803f4c6ff867",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2f82e80-7cd8-5057-8faf-de0d2878c8d3",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9caadcd2-b352-5fc8-99fe-cc4309a1228d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:750baae9-fc9b-57a1-a2d6-0c86fd29b73e",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737a48c5-b389-5d8d-90f0-86920c93044e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:211f2201-84e4-524f-aa04-588135dcf9f9",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd325ae-00f3-5e2f-9a4d-d866a18e7832",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f25c2be-8c88-5052-bcce-34f47b630d10",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e54ccdc4-d314-5008-982a-e78779d7a95d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.29-tuxcare.5"
    }
  ]
}