{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6a5fe985-50af-571b-a2db-746e7ec5187f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.30-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1cb6a2af-15bc-5629-b0f7-b91ce8c4efe9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e924a79-4fa2-5d6e-87c6-eeb3afd90e4f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011d3a4d-08fc-5ab2-9579-5f8ec36b7859",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dfd117a-6f64-50d1-9c0c-a534549cc2af",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de10f5de-44d6-56f5-aea7-ba4a981bf2d5",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4960601-a628-594e-a883-0c6f61c42369",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c68047e1-6fcf-59d4-8600-060c160b611e",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9d8691-9afb-57a4-9e3d-751add8f66a9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:345dc85d-3dc2-5dc9-92e0-d7413561651e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6546ae42-a7c9-5008-9483-235d0a4f5c24",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d858258-d364-5d61-b924-6a3fbe269cb4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b01876c-b15b-5452-b973-f055bc3a8d8e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebd2d332-a30d-59e4-aaa5-807fa473838d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec387b5d-c671-5a08-ae5b-ccbac922d3da",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:596ca3a8-b309-51d8-8386-d112e88dd8f9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8df3da1-62d0-5ebf-8f5b-360730c30fa8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b0f07f9-f85f-5eb4-bcf5-f187df36ce5f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a919891b-75f9-59cc-915e-c2344784a427",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f4911d2-9a88-5f65-b834-8db1cbc8cb19",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03be051f-ddad-5a52-8ad9-ad919b2756e0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc21f281-f1d2-595c-9422-6b6ccc68966e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd7f0b4-6c65-5048-8eac-b6fafd927411",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be59aadf-4031-526f-aa7c-144d2a601024",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc08211c-5810-5f17-9ccc-d9606985c455",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4ac8f7c-7a6c-5e2a-86b0-44bc90621336",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e2bd5b-16ed-5e14-9348-21bc4973383f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acc73f27-8315-5688-9954-71f65ad4f1fc",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3f48879-d4ea-5502-b639-7b55703aa207",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24c6748c-bc8b-5a88-ab2f-58a0d0f95918",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68dcdd1c-42b0-53ee-9347-96ea4b957b70",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a8eca7-5e96-56ac-9007-0f8679766fd7",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ade282eb-ff79-5a8c-82de-0c82a58257aa",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d407e80-20c9-56ce-8fae-5a9a1745e65a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e09e885-be8c-52fe-a3d7-4ca8cccf626d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba8b4caf-4956-5675-a701-8abafda3e5d6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee9f010-4651-5708-81c6-5b4031540199",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.4"
    }
  ]
}