{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:05d82c94-979c-5af1-9b1a-2a29679cc8fc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.3.31-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:35785fa2-3498-55e7-b57e-e148ad12ed9e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e808872c-d153-5307-b701-53d7a7f94c3d",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da5232f-c544-5248-9840-088dc2a25c87",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b824459d-c1fc-5b29-a855-1f28698efcd6",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6692dacf-af90-5117-8e63-d915e1d55b50",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a1f4081-d1cb-5b68-ac4a-7bdc58af2474",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9b3cab-c7de-54b5-bd77-4b7628df958d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37fe7f13-3707-5bff-9820-fcbe10c51744",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37347c10-ace8-5a70-97f6-eab27eb04d9e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15c8c3a6-baf4-5f09-b9d9-5ed96ce66916",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4abdf6cc-2135-51d5-a96f-d8881cadc832",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba2997c-4f00-5370-a2a5-406db8fbf8b5",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-web 5.3.31-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab507eb4-2889-5189-9b8a-026d40a3ca9b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b4b5c3-366d-5e25-81bb-c514d07bff41",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea586352-7f3b-595f-a0d1-8e770c0d628d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528fbc34-c179-5339-b258-119be605d9a4",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1fe9d1b-b0ab-537f-9839-1e60761fdf08",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2688f0af-999f-5d4b-ad48-1691f9cc37fd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d5fbb6-722e-5da4-8d9e-8b269c702465",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcd39f6e-2576-5f37-8810-1dd4dbb3e999",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de87f679-8fc1-59ea-9455-1c43eecaa4c7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b6f89f-8c3d-567a-a756-29a6b735a0d7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e09a9e3c-ffe7-53d8-bf87-07cae9c1382f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.5 of org.springframework:spring-web. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:363f5336-675e-5b85-9ffa-25fc30582983",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05622d8d-5348-5180-9208-99122b89c9e6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c81af2-535e-57e6-809d-518453a9ee8b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e99af21-9909-5cde-bfbe-04c0b3b79166",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a12dd138-b777-5c81-a8d5-969b0f75e89c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4212bfc0-f350-56f2-aa4c-484bc67bb4ee",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e3270f7-946b-5b69-a5c0-afc10dfe528c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56e3e844-e0b7-5205-a6b5-c3e3a5994ccc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134ba850-cec3-59b5-bb38-93ac0d08f0d5",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b2a467c-a652-5f55-bc05-36040ec0083e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef546549-a735-5d0e-9b56-a05b002e2535",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:969f8941-3fb4-5660-8e9d-3f9a3d3f5a50",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b03ad9d-b2a2-5347-a398-774b20929d50",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbaac9d6-fdfb-54ef-b641-522352119c87",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.5 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.31-tuxcare.5"
    }
  ]
}