{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:614a9990-50ec-548b-b70d-e7d807d3b0f8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5",
      "version": "6.0.12-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-34053",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b4fb0dd3-9229-5b1a-a77a-c2471ef910e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:23bdb030-426b-5fa9-9797-dfdddf6d47c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7fab3017-82dc-5782-b730-e083ea9a62f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84e3b700-ce37-55a3-b0ad-f78c123735dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d549ec8-93f2-506a-92b2-3ce26477dc2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fe16f828-d87b-56b5-b410-6cba7a955fba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2fb6c7dc-5017-540d-95f2-80a28a681c31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b61f4335-9b3a-50e3-8b5f-7ed2145f4826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fb388d8a-b3f6-502f-962d-e0fc0babb01c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:09b50267-18b1-5173-a699-7d4d5819a72c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cbc55c0b-9aff-5bcf-9175-eeb8dc043c9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:18ea6eac-05d8-58af-9a23-ffe0c9266e4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:286986f7-c3a6-59f1-8331-79cccc5bdb7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:13c6122a-5435-5c34-9e45-ceca063ee7a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b91ce872-2f62-58bc-b456-62c2b378b341",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:93912a14-b587-56b2-9de4-8f3c38e5dfbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5115b390-5e63-5233-83cf-bdd860efc344",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0f42e9a6-eaa6-5c04-a452-3d57b5915214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1d7036d7-f599-5f99-b55e-9f6ff4418261",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:365b3034-30e1-5208-a7a2-027f420e297e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41839 does not affect version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc. Current version of spring-framework is not affected by CVE-2026-41839 according to the vendor - https://spring.io/security/cve-2026-41839",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7edcae4c-8417-5881-a728-f0be452814f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1d675e80-0dd7-5c24-9652-2d01c6d53a16",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f005aea1-6541-5732-ad22-f1cbd8494e85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:05f6882a-4021-5ab7-ac79-006a409440be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7db3774f-c00b-59f9-945c-1dba54f12cd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0d426a54-86dd-556d-93e7-f423bb6092dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b2edba2-af8e-5296-abfd-48849c009acb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:78b8ba57-71ab-53e6-80db-ed7f59217942",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c40dd3fd-d0b8-534d-b2a5-5fc7f808f8ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d0ae721e-3247-523b-a554-2bfd7bad69fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5a93c4f1-0b03-5505-a1ad-18f82a8d21b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4ad9fc57-715f-5b13-bf65-c34428206db8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:56517a7c-d16e-5c00-9a37-15b7d6900cab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:40e8cbf9-44d5-5410-8309-d0fb8e9889ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d4a04d1e-1e41-5306-b2ad-b894c157260f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:189051c6-072c-5cb1-bfea-a25b1886efc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1e4cdac8-12aa-59fe-bab5-3748a503a2c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:608763f5-1fa0-5447-9298-5b521204208c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9b2424c9-67f0-5a1d-a992-4539d374deae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b9274f7e-45b1-574c-afb0-78ba8ecc4a53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d5734fc-a90f-5b52-b228-74773e83e1b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3e567d43-72bd-54a1-9323-7ce1ca9be888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bbe66ace-8d4c-52bc-a6fe-188987387b26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0ad08427-1e89-5e20-b1ff-d86494892881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9b3714f2-588e-5402-89f7-6a723361e347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b3e2ec2a-1da9-5019-9d44-7c62a2a8f633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1b1894ba-0fdf-57ea-8bef-a53a1b517b37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.0.12-tuxcare.5"
    }
  ]
}