{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ec520dff-95b4-5af0-b639-eb7d8ef07226",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.29-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a831b3e5-91d6-5903-ad41-f75e96d10f6a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81cb032b-a8fc-5e3b-8e46-1e54805e1d51",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd0fafe-4e2b-5552-9700-187ddf6e4c81",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52e9ee9f-6b5a-5de7-b709-171342fbef19",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36634221-3385-50aa-a4ee-70bbb832b784",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fa9c826-0a6b-593b-a2a2-b911903e2ba6",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7963332-8959-5e24-b31d-83746745dacd",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34a59fb-517b-5710-a3ec-ef6c9f161934",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c13281-4402-5329-a898-75fceb95937a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:babbae70-4091-5e6d-8423-93f250bb62a4",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d29b301-ec5f-531a-a2db-7bf1baa9e249",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dac2b55-b3ff-5aa9-8b34-2a3014aff879",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.29-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc33e91f-cef3-5ecd-b0ad-873dc9d033fc",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac68ab47-8f41-5f0e-8690-f01faa0938e5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb2a679e-1ebe-5856-8ea7-4b819e8651a1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:755fda94-499d-5aa5-b7d9-792a44faa469",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56e37c59-2d4e-524c-9eae-df2146b1bc36",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29b7486f-c79c-52b5-8be3-8d549ebdf143",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd1e4276-9e39-5cd5-9e9a-186e13754de4",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cd60e51-ed4b-5f85-9217-caa35194380a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bda8d71b-a79f-5243-9df1-a6875e72e447",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65bce1a9-703b-5da3-885a-983b1b0f5a68",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65186c82-97b9-58a2-920d-78de50fe8f7a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.3 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bcab48a-f449-5c7f-a8d1-ad7eb04d8b99",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2835fda-3dbd-56cb-9635-b73ad4aaeab7",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2efd75-f4ce-55eb-9790-bcc9a11d23d0",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aedbf22-a2f0-519a-8e1e-ca7cf416987f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287e34da-bfae-5aec-beda-c3374ae479d1",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f6c565-dcdf-54bd-b2e6-54574178ab50",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7756ef2-3d0f-57b3-afd4-af9ff06c0fbf",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41a0d4c6-bb9d-5459-a5fc-821b45aac181",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8dc9b91-2ab8-5fc6-8d3c-f46332592067",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf68aa2e-7842-5024-8432-e37ce6d77d78",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb8cb71-1d6f-5824-af54-0837ebce4c7c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:316072bc-53e4-5be9-b296-44a85f933958",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11324f75-015b-5811-8330-3f8f63f3a298",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cc23a32-d954-5542-a175-c03b29037731",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.3"
    }
  ]
}