{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c759dd45-0bf3-548d-91b5-0947981bd7da",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.24-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:848db8fd-2d09-5c19-90bb-6cca0b3fe47a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d6872f-03ff-5425-8347-efc843b59162",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f53bd40-36b0-586a-a3ad-227d0aec3cb1",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d4ae65-24a3-512c-9f06-10784bd6c453",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b1445d-7f6b-562a-85c8-bdb5ecfec7aa",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:873e3d25-7c05-54e9-8f91-eccbb7bd65bf",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81c20330-e55a-574b-81c6-ce704cdd8630",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da99e69f-649d-5e8f-a4f3-09dee7d87e2e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cd1b5e0-682a-5fbc-8543-c69bdaeb507b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8f27bb4-c971-599b-b486-bf041ef0cff5",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0884b05-9cb8-51e0-94ae-e54510361283",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2cbe35d-6bf3-5a7d-affc-cf4c4b074295",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09b4770-89b9-52ab-923b-ec639537de48",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639f28e5-feff-5be6-b84c-fe8173739a20",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a5387f-7a16-52b9-979a-df0da70908dd",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d253475c-ed5a-56ba-b262-eb4b5d75e595",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fce4e60-d202-59ce-9a3d-73812c76257e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cc12166-0311-51db-88fa-afac85ea16b6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be71bb21-1db3-57be-819d-c88bf8b84580",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f2f92ba-f264-53ad-a7ff-2f9f493da966",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b9fecb6-00ed-5a85-80e8-615e15884a22",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee387c9-6bfc-51a9-a31c-8828b40c9b99",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca537897-bd68-5511-9eba-2f79cc8de5c0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07f3dabf-bb4e-57f0-8049-ea8b9f899177",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94d3cd70-dc00-5ec6-87d1-0ead24e31f5a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e091bc-7248-5e77-8630-ccadd77fa37a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18af18d4-13f6-5252-b6e2-703bc2dc4642",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2730a1-5fa6-52f5-83c7-9875ab2f70c9",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd510750-3863-5374-9931-2137149e7744",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:719e6ae6-a5d0-5975-b962-0375d3240630",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f445447-df0c-540b-838f-be1bce24f6a1",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786ffcca-4970-5522-b447-8f80c5fbedbb",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7508612-4053-5544-976f-ce9da9d3680b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d15b19a1-a53d-5de0-9f90-d2251096f21d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9b4cb50-91d3-51e9-983d-e4f1a1c68b3e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b18cf6a9-0f09-54f1-9d3b-952a80a9e301",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3da45159-7ba0-54b6-b042-e26778a5e2df",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64501067-b894-537c-9f8f-0a8c2619daa3",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0717a847-326d-5a56-a891-c1705d3715eb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.24-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.4"
    }
  ]
}