{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:537cfc57-c735-5365-bed6-028572016ffa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.37-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:62ba75ff-7e16-505e-9ddb-4ffffb1b2ac9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60495577-23e9-59b4-8271-2f89b0d29676",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6781371-b09f-5838-b2af-41060bade52a",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05fb95f1-7cc0-58ca-9810-2c6339cce1fe",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7089013e-8af4-5990-8969-601dbfba938c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7c7b83c-5ed8-516f-be04-a1904feae474",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1099e624-9b92-5109-97a4-aecf857bb2ac",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9902cca7-e71b-5c89-a27a-2eb5050d3ccb",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20ac4c89-0400-5de9-88c1-aadb9b21c618",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2763f2-39a3-5a06-9dc8-b665012ec4ca",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a8fdcce-359c-5c4d-ac36-0e550018c57c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96957b26-8db0-56a7-b87d-426cf2fe4b2d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b326f97-05d9-586d-bb90-25cfd1b98c70",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99732531-c3a9-5feb-8d49-32cdb908ef76",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:031a45c7-2a12-5ed0-9eb2-9137d12107f4",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c23a6d44-f147-5b49-87ce-fa1e6fddf107",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dcb57d5-14f7-5deb-b016-1e43f30dd3e0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8be08297-9b53-56fd-8dd7-5ac55f56fb70",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c7cff3b-fc43-5d42-ae0c-8ea89ff1cd7f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:001129db-3b0c-5bb8-8752-0aef5ce1a20a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1f93f0-6efe-5747-8ba3-5e87b4653bc0",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b20294f5-5144-5130-a13a-3b9053bca485",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe57348-5ee5-5066-bb7e-5e298f5b9bfb",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6829247b-37cb-5536-b523-db40c3444dbb",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4196c407-2db7-53a1-9a27-1cd0fc5e4476",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da20f5f5-40ab-5272-9bcd-6c6376ccf719",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a149ae1d-8a3c-5d2b-bac3-4a7793400839",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27274875-f7e3-50b3-afa1-a906fc4131fe",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:588c0d1d-b8f2-5f13-a1b1-b7b4fd061548",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e025911-868e-5982-923f-e2277f769b47",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11312847-e2a7-5533-9ada-1fd75d04795e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:709b3d2f-dad9-5d4f-b2d4-bb46b2c74292",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a828572a-abf8-5c8f-bd05-5b5405a67231",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.37-tuxcare.8"
    }
  ]
}