{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:03669e7c-d44c-50c4-b33f-44e8114c23e7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.3.39-tuxcare.14",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ada577a3-058a-5518-9b40-195929a9046f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd4f8c8-521d-584b-8d6f-c69955014414",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-web. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34705429-cfb3-5691-907b-71142b7f7011",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a4940e-6caa-5f66-b3a8-e23f9a2e0051",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d050e8-6845-5ae7-8c1c-a301d916377b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d5b21fd-ba20-54a3-9ddc-ad184ede0e29",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdca124e-be7a-5d38-bbcd-cd9c31f0e7ec",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a6a5039-2587-5401-acbe-89c9c8a3b035",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-web 5.3.39-tuxcare.14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a345938-d1b1-50a6-84bc-03e1ed148470",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27b59b41-d3fa-5aad-b40b-aa03e3980abe",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebc5df26-a5a8-53d4-82a2-27f710166088",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad5b96e0-7a2c-54b0-9423-fd7f01d0ab0a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eae15a4e-9d8b-5658-a784-95572023f148",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:181f4d46-c9c3-5ee5-a243-8dbff7ca3c32",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1675310a-2923-59b3-8f27-5690f71ef47a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75ef1036-356b-5e03-8493-8adfc48df4d3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f775b67-7f39-5688-8c4f-1893eca5b66e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ffd64fc-46f5-55fc-8e75-e0fa368a533a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2d686ae-90fe-5b9c-958e-d7beb2d9978c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-web. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:405cb155-d59b-5b39-afb1-4bff188aabf5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62c9268c-d704-5610-a728-a6946f7d3194",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe4289b-766d-5621-9ed0-b1ff56486d3d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe3b351b-8714-559c-8f2b-767328ba7e8a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478c8f20-3023-579a-b32d-ec2dabb609d6",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f44f55-eedb-5348-8267-198d2481c4a6",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d18f53-808a-5ec7-ab2b-7f8cd71da2b0",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9441b8d-30fb-5836-bc31-27cb4ee48f5a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cfd539b-4c51-501c-a858-2479aaffd596",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46cbab9b-a0e3-5f30-9776-97c7db85a07c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9667e51a-e71f-5b2a-8403-1e250a268285",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f096aef-2d83-5b25-8c8d-af452e5b9cd0",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aade28c3-cc0e-5e13-a4ab-ef65fa41f080",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66fe36c0-fd70-5fab-bc68-753d515f87e4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.14 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.14"
    }
  ]
}