{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bb6e9b90-b32c-5cbc-beb9-ae73bf6b31a4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.39-tuxcare.15",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9c7532e3-1042-556f-9c0e-351dd98ae43b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1877c2d-5cca-5232-8c5c-faaa2f8696c2",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67340ea3-7e77-58f4-83f2-7ef5ee2b0f61",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518a56de-a254-5569-95c4-2873c5020a8e",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771783d2-af4c-539a-8f3d-d4d85afc015a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee4f76d-5574-5aaf-a35e-7c83d596b735",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99dfdd9e-3c52-524e-bb31-867c15adaa6e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31bd3f15-44df-5c88-b239-425c8a0f6909",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.39-tuxcare.15."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec74fcab-edb8-5def-b553-c0bcb6172acb",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be6a2261-7ed9-5fae-8a56-596c75f4b994",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a7035f-6dde-5b01-8135-7c4de2d1cd7f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aca5cdff-ffcd-505f-b08b-5ffa0d3c9f2e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c08c12e0-c01e-55dc-83af-16cde29b7bc7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700d2521-2e2f-50b1-aa3e-70b8d89d3a0d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:775e917e-1c57-5d8b-8df9-ce8711924042",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:538d0484-74c5-50ad-9f5a-924aafcb2a1e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:567b5314-c290-5f28-8015-ab9c815545d4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ab15c14-026f-575d-86e8-187fde5e98ef",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4167a3cc-1d07-5398-8b56-17c2700795bf",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd0fd63-3d61-5cf9-8fb0-32dec44c0d3f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11bb5de8-b662-5268-bdd5-393a694800fe",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a8d724-1692-5b0e-aa4c-e9d6ffdd6b77",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:311c177f-06bd-5403-bf75-e7eef7da9672",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98de55ef-c516-5fff-8cd0-f7c0a95f99ac",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd0e310-a5df-5e7e-9b72-0ce096748894",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c32866-a130-59b0-b721-7ddc0bb88c37",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a58504e2-c56a-5aa6-89d2-a0dab886e487",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e2dd888-d64b-506a-bcd1-d3037308c161",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b722b76a-d97d-520c-a314-91fc644b57a1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f0b598-826b-5b52-8751-b3a3ac493da7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:131eeb47-fe3c-535d-982b-b5fd39854a13",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98636fc0-4b77-50e4-af51-6520b0aa24db",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d24ab24d-2a81-5394-86de-0af50af7fcc6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.15 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.15"
    }
  ]
}