{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:49806a5a-f0d6-59f2-929a-092a083e319c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "name": "spring",
      "version": "5.3.39-tuxcare.11",
      "purl": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bc89f8e2-a7e4-5e82-ae80-c8c9e767c396",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30800f0e-570b-58e1-b7d8-ad092a8356fb",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.11 of org.springframework:spring. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d93d4f-9cfb-5b80-85b2-aa3d0a16df51",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f535e06-021e-5490-aa00-2261a9c54be7",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dfd49e4-5b6f-5a85-bb93-745c0f204994",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aba30921-3062-5682-827a-bcdb79862711",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2622c20-d7fa-5b2b-b60b-2cb05394a217",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0293b74-ad1f-59de-83cd-fbc419242ea5",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring 5.3.39-tuxcare.11."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c73f1c0-dde8-5307-82ba-f77d5f719661",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e3f144c-3911-5f39-8499-e24e219e4a23",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:861c506b-d1c6-56c0-bd60-83f0e802993e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e047ce8-bdb6-5bc7-a7b6-f375210d82d7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88b03ab6-e5df-5f5a-bee1-f1156ab72ba5",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f253d0f6-c295-5cf9-aaf5-51f18965043c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0caa0a4-0b58-5737-919d-cf6b0a94a016",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d079e7-7e38-5e51-afb1-ef88b7180864",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4f7208-6d0e-5309-9bd7-4ede1603e04a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a240a131-d2be-5588-8e91-574d417b9f9d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae0bb77-6a62-5c89-8425-ec0941af59aa",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.11 of org.springframework:spring. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b3ca285-bdaa-57e8-9917-14f815b6447b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a1108b5-54e8-58a8-a764-de804c21faec",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95e20ac5-2240-5455-8cee-843b539993a8",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2405176-5279-5e7f-9099-37de5ac0238a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd5f249c-11a1-5252-996a-82cd81966156",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e22a367-4f3a-50e6-8110-94d172b4f790",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad343a74-2b85-5a0d-b7f4-5997c2930a06",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c1dff76-ab65-5cab-9bd1-1a14f925fc2d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a111cfa0-b4f0-542d-a734-c8f3a1e7b509",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:803ef80f-e890-5eeb-837b-0df7eb3ae488",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b935390f-1ab1-5a1e-aba9-77355d73f04d",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b1031fa-4e7f-5766-a10f-df9c6bf6a562",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b9b264-bba7-5fe8-bb72-285a6cc0e40b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e127347a-30de-530a-aa16-5f9f5e2556f7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.11 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.39-tuxcare.11"
    }
  ]
}