{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2db633e5-ea15-5196-b0eb-c4c617c467c0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.39-tuxcare.16",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:27b83d33-a581-54d6-b170-aa80d5fa1b5b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ec6eace-7144-5f53-b4ae-93ac9de9de42",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a55c63-456d-574e-b21b-01a56f01d8e1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b20c3105-cca7-580d-9f13-0e60814613d5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30f75d32-2cbd-5d6e-ae53-8f387f63f3db",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd8d4f0-e955-534e-a7cf-22a9d2debcc4",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3ac1d9d-bb82-559c-a078-9a1ce0debfe3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cca96d1-a85a-58fd-948d-ff35b57b3b40",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.39-tuxcare.16."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52212ad5-0aa6-521d-80ee-11c1a0bba4bf",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb0696e-3963-57d3-a5a7-e452dcf52635",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17e54775-e91a-525d-8b44-aeecfd137bf6",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdbc6cf0-0bbb-5c2a-83cb-484ae4f1035c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:830d658f-9160-5c6c-94e5-40b3ab38f888",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9f8c69-60a5-56d6-88f7-bf968c0ca62c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f41754-5675-58ef-a4b7-caf98c0efeaf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fb61dc8-5063-5478-9396-c6911c67bfc6",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44c72f2d-6ac5-51a5-8c12-54eb201836e2",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19aad283-8387-5be0-83ad-c8bd56c6dc32",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff390b1-62ed-5b3a-b8ee-26095849204e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b41ae895-5752-55b2-821a-81e997fce95c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bcb7264-e200-59c6-8198-54baa57a0643",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e73b2b-dff9-57c1-a04f-b072c7f11f11",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e786dd61-356b-5c05-b63c-36c8ce3882aa",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29e415a-14ee-512d-9b8a-d5ebc9a44be9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63ccc5bc-fc0c-5214-884f-4cb5c041be45",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ebeb59a-67f9-53e2-aed9-d192cd50dbbf",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50852c47-600a-5af5-ba69-47b596826af9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15cf33da-8fd8-511b-9c0b-dd8e97e23805",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf706b66-c53e-5cba-a035-708a4c3962a2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6282c1d1-3dae-54d5-b722-18a1c92bb1ce",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f8afd32-999e-58d6-92e3-8c5aa20c4a80",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b18a551c-c46a-5f18-91bd-63a25424774b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5465c36-9887-55c8-babc-a63856238ba4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.16"
    }
  ]
}