{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7c58e0cd-1ee7-54cc-a2e7-3433e6aca93b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.1.20.RELEASE-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2b254bc4-db33-5656-820b-935977c896ed",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ee12df9-0881-50bc-93e0-b876438a0376",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:057e0270-9eab-5127-b06b-07f6760272e6",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a378fbb3-809a-534d-9809-6c9b4a4ac145",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e8f37b-3374-51cf-aab3-f4372213be60",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe5e0698-461d-5056-b9ce-11e8b5cbe8a1",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6295a587-3dc7-5bf7-882e-8718f9fa561b",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9b2072-3895-5a14-a85a-51c3526db41e",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29ef1d4a-2fb4-59a0-9c6a-4d5e32dcd3c2",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd4ebc43-8ad9-5681-b816-79ebb5be25cb",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b79dc9d-b92b-5d07-a181-f29b3b781165",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ab85a0-9821-53b7-a8f9-a72ff660f033",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b379ce3-2e48-59cf-97f5-f16136c3feed",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87e65343-cddf-5a69-aa7d-b8a5675170c0",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca4d0b9e-af9d-5408-8fe9-46881e75f411",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e753588-1317-50aa-b77a-00fc14805326",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-web 5.1.20.RELEASE-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948b4a2b-53f7-5c6e-8638-d732799b3796",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b44c8ac-4d23-59b1-a7e0-19b9bff47ae0",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b28bee04-1f34-5d0a-bde9-6c673a8ca791",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:155d097b-72f9-5251-8f5e-fee1ce650d4b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b0c961b-f3f3-5758-80f8-13c097cc8cc1",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4936773-a559-563f-a044-44dca6158d74",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f681e6d6-96b0-5433-a4ec-0996aa94d934",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:487e409c-00b8-51de-8793-c6331ca4f70d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ceb888-308e-534e-90d5-df424e87f5d3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6202f6-e6e2-504b-b68f-bcbb61b0f435",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c0309ba-8d26-590a-a8ca-e317444cd037",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c979134-e7d1-5ae5-8851-b2cbb4d2d3ce",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0225a129-2c6f-5d0d-a408-44977d9765e1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99ce02ac-3416-55d8-a7aa-e298e6bd0e68",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee6613d0-5637-5f59-a241-95e10c76a25b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c93e913-40b3-5ea8-943d-819ad1de4527",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ef8de9-f59c-5c85-99de-cce65c59f976",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:079f9eca-ac25-504a-ab37-0512ac9ee773",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ed67d97-ac91-5495-bd02-6539acf9ea2d",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59dba4c5-d829-5406-9305-a8f530aa731b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c857cd-76b9-56a9-b409-cb0bcaeaef80",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcc02d74-91be-5441-b878-4e87ef372a89",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:494a1826-1c59-577e-9607-bb7dac0b691a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb43533c-41a0-5d60-86d2-d1b63d5426ad",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64864932-b895-5f21-a72e-4cecf455509e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5f111a-c39f-590e-849e-2930782e569b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE-tuxcare.3"
    }
  ]
}