{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4c136a94-8d1d-52cf-8eb8-b077cb3ec3a1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.3.30-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:88605204-f016-5e09-b273-7fbd75a7ef18",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1205b398-a52b-506d-b850-d77e578878e5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6f5e8a-ad27-5cd0-8972-bc87f4055f61",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efdbc9a1-7df9-5e1f-aebe-9310c6d676c5",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a96c06d-03d8-5bde-8654-13c012b83d4c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c1d5422-f6e0-5702-b7d3-566fa2053bd7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad5a6638-431e-58db-ba8b-75b95b1a4865",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a31971-7456-5b08-8f22-d4c2fa5c34de",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53083f05-167f-56ed-b0b5-2b82512d29af",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9a16f77-b155-5830-81b6-54d8c0f72fec",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22d7af80-5545-51bb-b874-0ac550b08d4c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f786e924-123e-5251-a631-7ab738ff2faa",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a4ba71b-c778-5d1d-b6d6-dc5eb15f87f0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315b8b25-d46b-574b-bc27-886aa2051112",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da86da15-54bc-5798-8275-3b0e39f3942a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:127d3f5a-3b47-541c-8856-7333477fd569",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2183b3a8-53fe-50e5-a237-7bcd952bbd34",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6cef67c-8910-5b4d-92db-c789bb33a5c3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79e3198-0acf-5589-9dcd-349b9ed4bc8b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97daaee7-8b04-5cef-8604-85bea4498ee4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c780b8-63f4-5492-bbe2-95fb17fa87f6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:105b0b26-8d36-54c0-bd97-0cb777a265ba",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.2 of org.springframework:spring-web. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3a7884-6f99-5648-836c-ed01418fbe29",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:344b887c-15a3-5699-857f-22316f57709f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:406a3510-c0b8-5a08-aac3-63310dda04fa",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb806231-6de8-592d-b2eb-a7da80e7183e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36995f0b-32ec-5eeb-a256-93e1e5ee4746",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1406e0d3-bacc-5f27-8779-f60c550782f9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eade54e-5037-5f73-89d4-49a4722da7c6",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c5af72a-eac2-5841-b01b-fb0acd10f771",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:342fe0c6-89a3-5c56-a67b-a3248f6cd6eb",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da1d377-7a5f-598b-9d10-a688e41e5ac3",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d33c9176-3513-5f80-ac00-33c760fd4c8a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a247fdc2-1d2d-5bf3-924d-3b52ec33846d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a9a745a-cf6c-5e8c-bcae-5a66c21f4ceb",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ae6fdc-bd48-59cd-836c-8598861e51d2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.2 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.30-tuxcare.2"
    }
  ]
}