{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:70e24c9e-3663-58fd-bc74-29b1e61eb42c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.31-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2d3afdb4-a6a0-59ca-aaf4-6fab816aca85",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b69b3edd-a26e-5922-b254-a4e8eb9e9ee0",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95d6dafe-ce8d-564b-992a-4ab448fdaa86",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d9f57d4-b116-51c4-a739-48b208828107",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b03161ed-996c-5b10-96c1-21a6317ad034",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd29367e-f734-5344-91d7-c33d95c5b73e",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39e8c4a2-41b1-59ee-8d99-75ba05d6246b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f32902b3-c85a-5cc4-a02d-b4abc2c654ce",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:255dffbc-5694-5ec9-b88e-c812ebdb1d3e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c2716b8-7688-59c6-bd30-61b00cbfcd50",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4420d352-a954-5046-a9d2-352f88da78d3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62b95a93-3a1c-5e0c-89b9-1f93f828c2ae",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.31-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7068b118-4478-59a5-8308-56285266e8d5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29908504-8bdf-5092-ab36-fd5a40faa9bf",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:874ea584-e707-5e07-a50b-05cffb4022eb",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63fd4ee-6f00-5d4b-8fa1-c793a8379d88",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b95926-a924-572e-803f-2f70bb58dd62",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:289e0dec-bc9e-52e3-8380-9737cdb77ae8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af92fdfd-a323-5306-b155-fafbd060eea2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e51ff4d7-9409-5141-8990-f20f2b929bb4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d7370d5-37b2-5466-a03f-e70129ffc7f1",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c864440-e6d2-5da2-8fc4-525038b2cc71",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26c6b29-0716-50cf-8ded-95dd86002627",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b089d435-6599-5306-8b50-54fcd9fda314",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8dfdb1-9d48-5688-af2d-5fb998415c24",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28eb1e40-94c0-50a6-b902-7fe866ae5f6f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9355a9d6-4ee9-576c-abea-55ffa3d43ae7",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0b5590c-811a-5d89-9b01-9cbda042d084",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1f4af5-e3df-52ac-a9b2-0e2e05f53098",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc3b0f48-4069-5a48-b857-7baaeceb0a10",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ec959f8-65ba-5a4e-aef5-cee9dfc80724",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0808ff33-9383-5a71-bb7a-7a4e0e5f345a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ab51d4-10fb-53db-ad09-ad4158dd74b9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edc62b84-4217-5626-aeee-a156d2210a1b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:126e78a8-6923-56f1-9871-49473bd2b615",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d788dea1-b4ff-55a5-8504-eebc93abba70",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12ee993d-2ea5-554d-bc9f-2573c3d84ac5",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.8"
    }
  ]
}