{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d08db07b-0fb0-5522-a8d2-d711c359fd43",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.31-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0708ab97-7590-5f22-9264-44437116b12d",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e82e08f-a41b-5a15-b5f5-8c0231899186",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa6ff17-b85b-5d7f-beba-d1fb66986e84",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc605e5-13ec-5cbb-9734-86bffd6b5cc8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60fa6ae-ed94-5fe6-b46e-abdd3dc5987c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b4ee85-ec16-5e7b-9eef-78e0f364b322",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a58fb2e-339e-5261-986a-f86c5990b183",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1656bb14-9d02-5ab6-9990-5ce6c3925cd5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df627a5f-6617-5a5c-9e79-e18fbc348a37",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a57e7c0-f76c-596a-bfce-1add82aa556b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84d31b3e-9781-58eb-98f7-2c90d4fe66b3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2435997-59a2-5c8a-900c-7344c6e93892",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.31-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f258ee11-0939-5fc9-a9f3-ccc8d419abf7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba27e39-79de-5441-866b-e56dd6c03ca3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ad8ca84-c5a3-5102-bd92-451a93d6121d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08089b06-e174-56a2-9362-29f71f3504d0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05339017-41a7-5b4e-a294-c3243f37ae00",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5d4f51c-dd55-52fb-befa-205e56187a52",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3770cd-8811-5a75-80cf-451266628e56",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10ffeb35-4b85-5ce5-803c-a2b4ce6ac1b6",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c30773f-9e5e-531c-8558-b67c38777e85",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbfb5aab-3b11-5a4b-a660-0b7f30817d68",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38cbb91f-7386-500d-a772-abc603d6e57e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4457dac-ec93-542f-86a3-88bd72339602",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:787d3024-4505-590b-91cb-3e362a738361",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a6305b-bffa-5a7b-8f47-db763345d163",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ce48cb-4957-5681-b83a-7bf2da1f2c8b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8599058f-4705-59dd-9615-d3032b66f956",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80431729-3667-52a5-9c29-d2306e54caaa",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ea51f4-b7fa-52a4-a297-dda872cc27fc",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f952e57-e743-5ab4-b97f-aeb55bead664",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaad31c3-8661-5542-9a3f-c6729bdd1d15",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518ff612-5bed-5456-ae83-909ad5e22c72",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c9cd6ee-2647-56d7-ac5a-c8698497f431",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89ef07f9-639c-541b-9590-d402f4641388",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dce6740-4c37-590a-bc05-3664a19de4d0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59cc12ee-1cc2-5a01-bae9-6e994dad108d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.6"
    }
  ]
}