{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f8232023-1cb2-5a19-b886-399e42086f66",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring",
      "version": "5.3.39.tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3ae0cb1c-c5f6-50a3-ae30-1031313deaf8",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26b70496-3e51-54ee-b386-dbfa11e4c07d",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39.tuxcare.3 of org.springframework:spring. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cff891a-4ccc-55c5-9831-650e16f8cf91",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:799a511d-543d-5b62-a783-f2af5daef015",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74f544bb-f460-5706-8428-5fe9a97b820a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1cc9fc-ccf9-5ebe-9f4e-496bb690eaba",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e34b73b-d9b1-5921-898e-3fd7cb2955d3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:661e6dd0-03d6-51de-b61c-532964b9ca4b",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring 5.3.39.tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6a6e029-1245-5bca-8627-387583e6c8c3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04aab5b1-ba5a-5d4c-aeca-f49979c1eddd",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc0f516-b44a-5d60-a703-c68db6112e2e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d049237-f8d1-5995-b08a-60171575783b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6505652-2ff3-59d4-adf1-ab9097a9554e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d120b20-3063-5d2e-acae-3151982a4341",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0da95af-9ea2-58b0-b8f1-1f55b11d370f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df5c1631-6fbb-5d87-ae80-2d3a5f9df19b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c96ddde7-a1ff-56e1-81d9-dbaba38eaee6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:937d4fd0-b2c6-5a24-a9d7-38c864f7e3d4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12143d4b-0322-538d-b14d-ccf476c9dc6f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39.tuxcare.3 of org.springframework:spring. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33478917-b911-5aba-b868-de061be20432",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fe708ea-73a5-5538-8472-5f18b83bc94b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa4abdf6-6a0a-5959-9de9-e5b6ee45e0a0",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b913c31e-6574-5873-848c-8d0a576fb7c5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:732eb540-8cfd-5edb-8a4a-2b15000fe396",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:842c750d-c242-5db4-a3a0-dc319749e4f2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0f4b30-cf02-5ae8-9a1f-a3e567d09390",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ce8386-b155-5274-9b5f-61ced7f961d3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54d447d-a676-53f3-bf00-cba95f77ac61",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeed451b-29bd-54d9-a470-33c1fc733db2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c06ef8e7-4c65-53a4-8ebd-9a491cfda331",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7966d2a-c913-5e45-987c-1c345610a186",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f8a823e-08cb-5e0f-a2fd-6c06c2ea3abb",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6afa50b4-81e7-5a71-81f2-604d392a4393",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39.tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.3"
    }
  ]
}