{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2aa3de08-d82a-5a6b-a33c-787551e0b263",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.37-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f52cf060-67e2-50f3-8e8d-a6bc97b13be5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7b63db8-e614-5e1f-b08d-45ead519d935",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f6853f5-8aa9-55df-aa27-5beca7f99093",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72dc6c5d-3fdf-55fd-9107-6253052591f9",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:097e36d7-cbfa-5888-8b28-de5cd3f71a94",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad1bc42a-adc7-5ccf-bd11-1ff1ac3edabc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8442894b-b690-5f7c-81f9-6d1e8a4b5b44",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cd4dc02-b590-56aa-a106-68aae1cceb87",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8358c4-3b88-59d9-8e80-50997853a093",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3131fa3a-3e3d-5ef8-9fe2-b336092459fb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e314e41-f077-5dda-8fa3-5b47dba44ed0",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05199c9-502e-503a-bbc2-ccc258822489",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23b60023-9692-5c43-8e2f-7fd7886affe9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3eaeca-069c-51c5-ac8d-3a132c39336c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e806ffff-5e4d-5a19-b54a-f2f0497cbd9a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c068664-1685-5ff1-90f4-7238b82a54f9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f02884f-444c-51fb-b099-83f1869a7647",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b1d615-6704-5cf6-9ec4-4098095731e4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:029ae694-8f5b-5c29-8514-3a6a2c7975f0",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c8c8ac-3ab7-5fe2-b776-449cdaf27353",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f999d63-969f-59be-b829-d80108e7757d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78c26cc6-d613-5078-b78e-af236ba4d749",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f960b99-5a57-57d7-a652-6c7dbc16c3ce",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c5d0e93-5b22-5e1d-aee6-fbdb212a49fa",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a61b00a-7c4b-5aed-890f-11e8b8adf54d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e415b51-611a-5f5d-aab6-77ebdb9ee893",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7910af2-889f-5e60-b8fa-f0496ce626ac",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc47cfe-72f0-5947-a9e4-15e94baca642",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d1f46be-fc54-533d-ad22-24b47322381c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c612eb8-7cd0-5701-81a8-8cd5c3e7b712",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:007bd805-a460-5bfc-926d-74a46624c6fa",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d2ba4ad-405f-5249-9a35-35e3d5dfac7c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74510988-c81d-50a9-80be-9baeb7411a9f",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.1"
    }
  ]
}