{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:42a422b1-f794-5095-a68f-e24572cef13a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.31-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1c7867bd-9a92-57a1-b029-8ce55a87fd8e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb583dfa-323e-59b9-a1cc-8c4eab8f7ceb",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95604f68-0064-50ce-a7db-60081b1ff27d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0844013f-886f-50bc-ae4e-a4a742aa8fc8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a60c42-f946-5d2d-951c-2286664e2ee0",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ea4177d-d9fc-5c31-bd6c-eda166012d0f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:486e3c63-8241-5d0c-a24d-3174cde75d2c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97227b7d-027c-5d59-b780-9b7d178518e5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916e95ae-4bca-560a-98f9-fd9ed4128f4f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b5395c7-3408-5d8e-a840-640810d8c8cc",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd64abb-22d6-54b8-8981-48499000e388",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f15791a-f37d-56a6-8dae-d75cde0b3307",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.31-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfab253a-50ae-5afd-9440-c7b6e12a522a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:450ade24-fc60-5ce0-8128-80a1d2051220",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af11adff-abc7-521a-9f42-d1ff5812da49",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bd7b2d-92a3-5165-855e-fb94edefa0dc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1913b5-f811-5495-82ab-243aea216e87",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4494e020-0873-5cb0-bd8f-0fad798666ed",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e58e403b-86f4-51e1-8081-dfffcbae9cdc",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c479206b-f4bc-5247-8d0c-d10ddda8e358",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a68ae0f4-e02c-5369-87c9-ecfc24ee3d5e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:399bea62-6d07-5668-9456-ef7d494ffbe3",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c8e0441-9879-5e2f-8bc7-de1805e7b5ef",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.4 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c0ae39d-d624-5b43-892f-59db78696abb",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:588dba40-ea0e-530d-ae6f-d9a5b88aed08",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8124a5f-c073-5485-9ad4-6f77c0956e68",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2a0f3d7-4256-52c5-814c-4d2b4dd25e02",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dcf0a64-6f31-5365-8e0c-b1c141e587ba",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e53ab9f-782c-5a42-9f15-5f26b7800a66",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:361217cd-c8c1-5cd1-8cfe-5494bff620d2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:766db3e6-2fbb-5a7b-aeea-2d99b62d2ea9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b1aea3-84bb-5f04-a87c-3a73bd77140f",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25875e18-092a-5659-a2ab-647011218c29",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64206055-cbc5-5c1e-bbbe-e4a6ba8c9bfc",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6ca4a3-3cbc-502d-8f03-961a44ac7af1",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91038bf5-86e0-5789-8af9-22f5ba99ff25",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26cef6a-ff27-53a9-8aa3-60bb9fbd71ed",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.31-tuxcare.4"
    }
  ]
}