{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d9700da5-fda3-5b0f-99fe-6bb1016b9c1a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.39-tuxcare.14",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4699814f-1f56-5585-8059-eeeb5a8f446c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c4da7ab-69ad-576e-aaf1-332350a49c6b",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94248e0c-9b4a-53c5-98a6-76be652f61cf",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c958d7b7-340c-5ae6-a775-3b81255219e4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3f8545-a6f1-5bb6-ad5c-2a765f4e1ee2",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb9937f-2632-507b-850b-da5c25400841",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f981d6-37d2-5f6e-a12f-3fdec311c042",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a4ceadc-1fa5-5866-be88-023332e1b0c4",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.39-tuxcare.14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78e60e23-08e4-5ff9-aad6-531ce132c2b6",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65b7e501-7325-5c48-9156-a953dc3b5577",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8142606e-a03a-5e58-aa64-eb7a5f091dd8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c68c6813-25ad-5b29-b37f-df6fd8bb30a7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a926271-cf60-5153-8293-9709063653ef",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:819bab81-0f95-5617-ac25-1e4d9a648a21",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05b4bdb8-57b5-5774-a3ad-f93e17d5c366",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f11ca5a-fa19-5905-ace3-35c641ed159c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92b8019d-e16a-5d9b-9ca4-fa7e96e9ff47",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:861bc926-8462-556f-9d69-92b5db70e944",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdfac2c5-9bcb-5651-9ef2-91522ccea447",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95434c34-bbaf-5192-8aea-3faf52864a13",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a33f80c8-ae52-5b0a-9c17-e00913f83a7c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91f3266-9ae3-5360-818a-a4cccc45ba23",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e259c10-ea91-5fdd-839d-899bd026bace",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f0e7c3b-9093-58aa-ae3b-6523ab94f077",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b66c02c9-95e7-5015-8ab3-a3ace3474033",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:462be5cb-311c-546e-a55f-855fd541cf06",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41aa7fce-f025-5d65-b4cd-f8f36d815a9f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bed15bf-eb59-557c-ac4d-baaf14b2c193",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39a7d94d-fe3f-514d-8e72-8141ccdedf09",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:025f385f-b797-51b4-8b76-ad0206d2c37b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a581b823-962c-536e-a027-207244b24671",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcc41b5-81d8-50cd-aac0-4747b06ff59c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d13580-5f0f-57c3-9f52-f66e6fb68895",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.14 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.14"
    }
  ]
}