{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2a95fe92-9d20-5e86-8584-9f8ae397f1d1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.31-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0d0d6560-d612-5c16-b38c-e60fd247aa0b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fdac583-8f4f-528e-a6d5-9795c50c947d",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dbadfcd-c34a-542a-ab4f-00bbf2207fef",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70b5dd41-ab6c-508d-9d62-e90832e58fa0",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:665e0dc7-189c-582c-a082-de252aca717e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea0f8bc-6d75-5399-a7c3-6cb23e2ecb92",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0459951-3dd7-52e1-90ea-322f0e58e02a",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:625a6130-fc4a-5e37-965c-0c484284cb2a",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b17a4499-57c0-5c50-bcf0-5ba06254e918",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:638d133c-1d01-5fb6-8531-722a126d45cf",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:292ed406-0626-55a6-ac66-bb31df7b73f4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29277ee6-5c25-5d22-9e95-24d0a310b1d3",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.31-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45fdf228-ac7d-575e-a6fc-59fd3cdcfada",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9742e33-e0fc-5419-affa-b5983f34c979",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f6adfa-0f20-57a0-91e5-7a97fa713bb8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf26faf-52b6-5023-b659-84577d42170e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd216d17-9d7e-5ebb-8b74-4fed3240018d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:733cbfde-3433-54e2-8cf1-7278355aedfa",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d5c4f56-f3da-5c0f-9571-35e1baf40ded",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83c0a0a6-87ae-5bca-afc7-55446e1deb92",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bcbe405-5a86-5e47-937e-b261298fabc7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d9277a4-be75-57fc-a97c-2ac616cf31ae",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9b9a9b2-d420-5f1c-8d9e-3405a428bcad",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88056c5b-8865-5461-b15d-b93493937022",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d789c7a-c697-5200-a3bf-6d977a68b284",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3493df6-e485-506a-9903-a4b8cf19d628",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d95d2ca-4410-562d-b9de-6d3bdc20bf47",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bd4b942-a937-5197-ba4f-25cb438eecd6",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad3bb1ec-5b6e-558f-b65a-d7966e566616",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a8d36a-c433-542e-8fef-b135fe020e92",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90287169-3c6f-552b-8aab-327a44e988d7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ef3dfd7-98cf-5cf9-9783-6fc450df4628",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aab9635-88e2-532a-9dce-944e1a5b42a2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79398622-1158-5a68-b22a-7922ed232d5e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60590004-6a34-5318-868d-f213936d7536",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19316159-20bc-5c72-9b16-0575956ab386",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53002683-f76b-5146-b41e-13d6ad8e2bc8",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.31-tuxcare.7"
    }
  ]
}