{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54dbed39-0aae-5c9b-b6ee-3c5b0a41ea9c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-core",
      "version": "5.3.39-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9be84183-88a1-5c64-858d-79b38714dc4a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7369052-d840-51c1-8ea8-801b4b3fa066",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-core. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70829dd1-5bce-5f93-892f-15df3d66c7b1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d95905e-5003-5a30-8a5f-4576762b5f42",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bedef15-d8b5-5198-8537-6b56f91b4d18",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:624f939c-0ba9-51ad-9afa-7af1c872aa68",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:440919b8-1c6b-5042-8dc8-effc805238c2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:844a5ce1-616c-5ec3-bdf9-d7d36ba4f385",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-core 5.3.39-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:416cd560-588c-53c2-a5f4-8fc21b487309",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72746ba-b0ef-5243-b891-f2f0c70e58f3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:def1c5c6-4d3a-5192-bb36-8365031319c9",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c98771-d5ea-59ba-aa74-f2276a8e9be9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c0b46a1-747f-512f-8501-7eef98227026",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c26fc50-0bb0-5a5e-994d-bf7e626d8f9a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22ff328c-4e2d-5b1f-ad4e-10ef016ba3f1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0361c305-c5fb-50eb-864b-d5946855ad8b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db56d3e4-b0e8-50df-8067-d91e3b17c6e5",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adb3785a-61e3-525f-9f67-1dc48b6563c9",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:527aebe3-0fd6-58a0-903e-8e8b1e566df6",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-core. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1677102f-e7d7-5721-8cb1-ecae2c906a9c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cb25ed1-0eb7-5715-837c-1da719b59305",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e48169d-7285-5810-ac94-5a455befe41c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59cc71fc-c3ad-5ebb-8416-f700eeb0a85a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e95eda-e8ae-5b36-ad9f-6f0b142129f8",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31828149-e692-5d18-b26b-c20afec4359a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a6f685e-6b41-534f-96b0-f3e8bfd7bd7e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e77687bf-1368-5ae6-a7d7-b6171b5c3495",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84f4b108-e62b-5b5b-95c9-5c76a3065a81",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5963f86-fc7a-521d-ac3f-5c6ca2024fe7",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe109d16-37d0-52e2-b4ca-0f20576668fd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9ec6b37-705c-59e5-a1ac-143b766b3e6f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aabc25fb-679f-56eb-ae7e-f5bbe3f52462",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a6bdef-c3c7-5efe-9589-4e0759d1d0e7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.12 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.3.39-tuxcare.12"
    }
  ]
}