{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7f4a603e-10f2-5c88-9334-b7832e6fa238",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.29-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:30a46f63-0880-598c-a314-5fc4c42d01b5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da9b99e8-009a-548f-b94d-0d0e83198b7b",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c29b3463-6d03-5394-8342-f609674c00f6",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7feb1613-86d8-5ed2-a17f-07aa56b7d47f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfdc8e66-54dd-51bd-b8fa-61efca2b33db",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f638ce0b-c020-56c5-acb3-64c16450f31c",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcd5a3cd-d89a-5875-9961-da32980f9612",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce3535b-bf2e-5749-992f-f4985a0f4908",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6142d357-e976-5eff-b74f-a5ad139a39c7",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:743422c7-89da-53ae-857d-96fdfefef388",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d0506c-8880-5e0c-916a-e97e280e0088",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c9b9f2-9be4-5002-87c4-c83cd76640af",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.29-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4da63c-4b2f-5d50-941c-754ff8b1ee96",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e94402dc-dde3-5f3d-b1a9-6dbb616de4a2",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a6c7b3d-1bf8-51f7-b044-f39442ca7da7",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c478383-1d50-5491-92c8-ff4fdcc50da6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa2f47c-1a67-5b98-9aa9-bd7ece976201",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e985137d-264c-50cb-8d83-631f9174a87d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:233b2565-ad35-51bc-ad5f-3ec938fe6a2a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d7af872-3fb4-5a84-9aa0-a76081374e92",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99edb31a-bf8e-54b7-b8d7-7394fc849fa6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3258f417-d7d8-566c-b0e6-52e3f799304d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0e9f3e3-95e1-5766-85eb-7b654149913c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a24f9796-af1c-5dfa-b96f-f5dab98da925",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c2fa4c-dbff-54d0-9525-1beffb6e379e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e782b961-fbdd-57a3-904d-9f9a6a425943",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc4ee97-73d7-5c9c-a7ce-2c11204ac4ab",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a03beebb-46f5-59e3-8985-3d122b58a156",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd79b0a9-b54e-5684-8996-1fef08310be6",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38f44a16-8ee3-5de9-bf15-89f4557e443c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e769ddd1-9992-5772-a819-efea4f877239",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4960cc3e-b38d-5f32-90fb-f6bca0169087",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7b4031-6893-5d1a-9ebb-35e6a0c8e4dd",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c6d43b-4c75-5da9-8e8a-9e8e08733308",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:354be30a-a7a2-5989-ba38-a963db78c67b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bb9de41-204a-5e47-8d23-2a335bb1d22a",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45a9dc8b-69fa-5783-9982-079f83c48e2a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.5 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.29-tuxcare.5"
    }
  ]
}