{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9dbcab20-c1c9-5705-a107-5262ccf2fdc5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.37-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f2d4ee45-71bd-5795-aac4-d9df94bd08a9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d68b9c-8204-5e01-9634-2bf089e28af3",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b3bf6e7-cff9-561e-8135-d1d07b0ebae8",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0400890c-e205-5f3c-8fbd-dd971438ff3a",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e037fa80-73c2-5421-8792-d4425bf69fce",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddcb6a73-cf89-5689-ac38-76880c5e8a06",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca992e5-79d7-5076-b14f-9672a9412df1",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bef83caf-75f7-5dc7-b86c-9220f412c38d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8f30d23-abb5-5b2c-8c0a-0946530c2755",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:626b7e8e-54ab-57d1-a2fc-64d929014261",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13ad2f8c-7f96-5e7c-8975-314517e4a991",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77b0d266-8667-5f88-9ad0-9b601c6db6b7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81f93e0a-316b-5421-af3c-87f01ee033a2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230f4d93-07a5-5351-8389-61729fec788f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea2c2131-c121-57e2-910d-97f3f8cf953f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6eba127-d05c-5e55-8c51-a3004d12469a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b16212d8-c1db-5fd8-9e5c-389a1ed539e3",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a916b091-f5be-504d-8f00-467db59a1a24",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a2e67f6-cd26-533c-85a9-8a64763c9521",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f3bc794-3a4e-5559-9b17-0c94510f7c64",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3772a155-7adf-596b-a470-cdbd5b3a1134",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66a1cdeb-347a-5ed4-bdca-40478c2fbca2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b73a3cc-f2b6-521f-ae7a-01dc03b29ff2",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c6f3c66-8429-5fff-9ad6-f2c0562b0e1d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3322725-0803-57d5-91f6-9a3132f14896",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0059e4d9-816f-5002-8d34-30896cf8c182",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b03f30f9-ab92-537e-8fa8-980443773bf4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efc3a573-115a-51bf-a7d1-668024a615ce",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc767a6-8565-5de2-a433-80c9b2c9cd10",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bca92ffe-84d6-5cb1-9495-5f675d16ebcd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb8eac1-09d0-58b2-a001-38f71c005a26",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc10f711-b093-5adb-9bc4-8f36e8e9dde3",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9dae69f-6876-539f-a93d-e7c3858c33a2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.3"
    }
  ]
}