{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:18bbd64b-cfce-5682-80fc-917175410ec1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "5.3.39-tuxcare.13",
      "purl": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8d2af62a-e94a-57a9-bc0f-e759f4ed8738",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d204c913-3b1c-5a6f-b9c4-187ec090e850",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-test. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf214946-0a00-58e7-84c0-ced41cca3fe1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aecaa540-f22d-54b3-9b10-4128da1e5af4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eeab03d-48b5-580b-9910-8e23c5e3a689",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18ddd985-79ba-5fec-9bc9-312944df6baf",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b233848f-22ee-5e8f-bf7e-8e85f25f3fc1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e081128a-c774-5054-92fe-fd006386cfa2",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-test 5.3.39-tuxcare.13."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a1cacd-7840-5192-bca4-926881b0107f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1be987e-4130-5033-a96e-cd7861270241",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10741c9a-ed08-5b0f-9129-a02a3cc92993",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d78269e-d2e3-59b5-8ef7-d5a5419069c7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d8fb5fc-699d-5fa7-97b0-715a7fd15b8a",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d939fcc-4083-5185-a509-6b650d5877cb",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9131f88e-2980-5ac1-b29a-28717d63b724",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b27e12de-dba1-51e4-ae32-21b005409514",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adb48591-8a9f-5390-9293-1cdb60eab578",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e895e5-b838-56d5-8747-377518a3b666",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a35edab1-a819-50c9-97b3-2cb61b3a7f5a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-test. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66919ac0-b328-5984-a3c9-6b047fdb4b12",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82013f11-4183-51d6-bdd7-71e4035f9cdd",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b1b971-1f0b-53a8-95bf-bfb572d1ad49",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16bcb4c7-b5a8-584c-9142-a18fe344e414",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2a5cf8c-9b29-5bee-8c90-f1f2b9a07a41",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a6908c-d70c-5b16-bd68-7136fa58ccb5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b2ca90-eeef-567f-9873-890694caf8e6",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a68dd4-21b8-5c76-b37b-ed9dba53fc68",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:104a1c06-25f6-5bb4-a6d4-660be2b35e83",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d060c11c-1774-5dae-b00b-97e4ce2bdd7c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa68db4e-ac79-5523-b6b5-1c1a455957ae",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18a880a-bf82-5f03-9fdb-f73034967d30",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e12921-fb3b-5c50-98d5-f0a9a6f92bd5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb31315-c1c2-544b-a21a-70aef36fc416",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.13 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.13"
    }
  ]
}