{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:663f9c3b-0e3f-5832-97a7-6e061ad93b22",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.29-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:031ebdc4-3685-5f58-bdd4-ec384237325a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17dc03e7-e585-5e28-91d4-c701f7ea5b25",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85baa23b-3f4c-5bc6-b33d-dbc02a2df2a7",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac03802-baf9-525c-943f-0259e1b1c4f9",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba7f6089-0ba2-5f6f-8eba-e4f3169318f6",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4c600e0-0da3-5644-a4e8-2b5b89f22ac7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb7490ef-846b-5ca1-a267-0dda1010aab8",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc0eb6b3-bbb5-56ae-9f01-e5d85756c0f0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36846ef4-870c-56af-9fcc-cbe48735f2ab",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c4847b-3453-57d1-992c-4e75f8ceef03",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c857ebb9-0165-5170-ad5f-bd63f1cdf066",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2e03974-0549-5853-a042-ceff61013eaf",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.29-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2201289c-a93d-538a-8ddd-3fc0bad4a423",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:929d310d-4d24-5d54-ac2d-3aba46405c29",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1163e4fa-2631-5412-9eb1-ebf08e968548",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05764316-9113-50a5-a542-d66bca1256b1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9ac89a1-7442-566f-bdf4-73e86b9313b6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b87635-6373-529a-8258-95efe60e821b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c61e31ac-5a4e-5253-8770-b72c82f16c2e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2afd9a6a-f9e3-5783-975f-dde2f7b2e765",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:631e3c74-0cc0-53ed-b096-0233a4d6bd9d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22037a6b-f43a-5407-92b6-ed18ab2c24e1",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03a1264-c9ad-5ba8-af38-42c12d558062",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.4 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9f36a7b-9efe-5d72-ad1a-97869ee87450",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c2946c4-21f3-5da4-91ef-bb739dcd99bc",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a6be2e-82f8-5da7-80e4-c5b7e071308c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b52936a-2c32-5973-8113-19b2450627cf",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63bdb313-5672-5815-9b42-ab9de6ab3fc6",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01eb9858-3680-56b8-8d18-35a88764ef72",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e490a6ba-033f-5196-99bf-a3b15b96887a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20fdc575-589f-570a-9c50-dd99d3cac515",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:157881e1-88c9-5a3c-82aa-19c3f02738f2",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c28e80-91eb-5c9c-830e-c41f2b6cf64f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fa8d2e1-b4c0-5843-a9cc-c3fdf6696c43",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:485ea30e-fb78-54e3-8cd0-c32a5426011f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93a81b66-9f95-58c4-9d19-df6be1b8a5bd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d9a0173-b542-5a54-b02e-f9f76116f213",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.29-tuxcare.4"
    }
  ]
}