{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0ac37657-831c-5cf4-879f-d4f616be0332",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.3.37-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6fa64970-13b5-58d7-aef8-28ed7201e4a0",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b43f815-45a0-5f21-9daf-3070ab61ac7e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cfca2a8-8b1b-5f91-b4a0-857a798630d9",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60260b50-1641-5050-9719-3eeecfc0c8de",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf667cbd-03ab-5897-98bd-de64eae67935",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61705f3-0cac-5d34-bd4a-444c5d478461",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:902ddea4-def2-569b-b20a-cd7232bed5c1",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2585b810-573d-5f97-94e9-6a922dce4e43",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87dda4d4-615b-5a96-bb9d-3b5dfdc3814d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c90c6c-8b54-5bb9-88ed-e915b757a073",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a0c81d-7e46-5baf-8fac-2365196fc61e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:905c3773-1134-5673-ad54-00ca4c461b38",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:393cbcbe-ad7d-528a-bf1e-cf8823603d83",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b165896e-f2d0-52fa-879f-ccfba4937a87",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78a807e6-35e0-5dc9-b50c-fd93f0629929",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e2e7d5e-e67c-5f40-89e8-3fb12a4d5561",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16433d1c-5a5b-5d58-9898-5276223c5418",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4922945-148c-5f08-b0fb-b3cbc47b4cc4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da1ac657-8ea6-521b-8ef1-6d437b304503",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-web. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd81c33f-898c-5b0c-9308-fb91970cc32f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3347b638-f44f-506b-b561-0d9d1e9beeac",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1b8243b-8243-581f-a596-e2344ff731ce",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4969f053-e80d-5861-b38f-67c74f695dc9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bddec645-8b6a-5f20-a17b-f85c884ab78d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33e82fd-b1da-58fe-836d-098adda42d5e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af76c1e-bfd9-5d96-a6c8-74bdb0f2e39f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33cc9e06-61bb-5eb1-ab9b-64b788b7c1c0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff21da5c-98b8-5743-8b00-cf3ff8e2dc7a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-web. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5bb8fc-9fbb-5131-8c1a-bbb2983d9285",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b8f654f-4dfe-555a-9d01-2cb641200cdd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf177004-dc05-5dd4-90dd-672f510daad9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3686a1bd-f3b5-5966-a461-3fca6744dcf0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:769d7885-9a42-5526-a983-ee7909e34b74",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.37-tuxcare.2"
    }
  ]
}