{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4c20eba9-2c84-5d16-84bc-e466e3c66728",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring",
      "version": "5.3.39.tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:20517a1f-a591-53bf-9d79-01a08b56161e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:014f8c7a-87b6-553b-beac-fd256f0cd6d4",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39.tuxcare.6 of org.springframework:spring. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c865b69-0b88-5f1c-bab6-11f082db9c01",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:093c1c79-778d-5a32-9e0b-d82189e73f53",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19c6330-8941-503f-9c18-be7e538ff207",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:503bbaca-9da0-5b21-b2e5-e86aa3495662",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f84b76c-8dc1-530d-8059-aa7ea98e1e3c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c670cf-6a12-5a3a-bfee-50c793c5d43e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring 5.3.39.tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e1de7b9-6463-54e9-a7f4-431b9ce5d6c9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eb2c848-1f15-5753-9cf8-b3976c09b7c3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92fe1dd4-1e8c-5b6e-a859-bdae4102b378",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b695776-f0e3-5df6-b2ad-7210fe1fedaa",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de680bd2-baed-5d7b-9887-8b48f2ac59e9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee821f9a-4349-5207-a9e7-6170ce06b12b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc383701-45b3-5042-b6b6-63564516d73f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89f5f12a-0d0e-5423-9396-2bd265c02508",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fff0a694-d89a-5803-8bce-bd4e17f45492",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bb4b684-768a-5c26-b4da-a18290f04569",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ee75b0d-ffc7-596a-a159-17efc0a876a5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39.tuxcare.6 of org.springframework:spring. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e97757a-2263-5793-b1ff-ca2054262b94",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3c2cec0-519e-542f-9f9a-7e8facfcb6e5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ab1107a-c061-51d2-ba08-b2360659d9d6",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee7669fc-3c12-5ef9-acbf-6d680b00f333",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07462c8d-7e5e-5659-a617-71da5b24a397",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23562057-c5eb-5d7c-a98f-3ac5407ef271",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:883abf18-a44c-5f44-ad69-7e13bd969deb",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f91bc02-ec6b-5756-91e7-1c502f1104cc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afbb1bf9-7eb1-51b0-9979-a3e9677269b0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d56ba2-05cb-5282-955b-40a36c644a1e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690f8edd-c935-5821-a2fa-da0837a21842",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e959377e-9177-5e70-afa3-259c12f27958",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f2b376f-b6d9-5807-941c-ef872f588f32",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8bb4c71-917c-5f9b-9313-ceaf38ed781e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39.tuxcare.6 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.39.tuxcare.6"
    }
  ]
}