{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d29660e6-1d96-58a4-8d53-b924f7f9819d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.39-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:be60b821-34e5-538c-9e77-a6e989b07db0",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c23b35-e086-50ae-ac23-ec2624129387",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.9 of org.springframework:spring-beans. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ca3e802-c84e-57fd-836b-c358d1b442ed",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38bbcd15-b588-5361-985c-0097e056c0da",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ae87a47-7a6c-5d7f-abcc-0c2fca3bb173",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738e9bcc-3010-585a-8458-de4db18d12db",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d00c15-507e-5b26-a490-d22873f32d38",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b04fad0f-7dc7-5886-9216-b33fa4f7b575",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.39-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59748569-ee81-5dfc-8b77-24b933877722",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecb47ff2-b87d-531c-b50e-c84f7251cb7c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7491d181-9299-518e-b872-10691fa86080",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e0b221-5b0b-5f06-83ca-946bcbc22d2a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b183d9f-ac18-5523-bd5a-7de0a2fb6ee2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d671e00d-8908-5192-adbe-f8a3435c20bb",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6313566e-ccf3-5183-b5e2-301dac82241d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64452be6-728e-574c-a1ef-2b6fc7f2f16a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c316690f-488f-5225-bdb3-a5bd327ac112",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a11aa6e-61dc-5ab4-a1b9-ba3df3cb0f67",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e7705f0-c424-5cb8-b618-449ac1792de3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.9 of org.springframework:spring-beans. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42511ef9-6b76-5a27-95c8-49b84ad05173",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66576c2a-10fc-5935-bdb1-0a112d5d06b1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961d3890-e71b-58c5-ba43-f19d42c0412b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9324fc07-6595-57aa-bc2a-98bf6c39a266",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eac8f7f-5b70-596f-8798-408e984be3c0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae2f14cf-f6fb-5bc6-8d2b-4b5316dd0254",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:830727a0-c49a-57bd-a1be-80bbacf1ee49",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14b4a949-f8b0-528b-bb74-3730252a6cd6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c47c8d-21ea-5e9f-a600-b38705c8295f",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f693453-75dd-5f93-96a2-5862888f14e4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff4d844-aeeb-56fe-98fa-b5ca9f99cffa",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a19957-7be9-5b94-9b2a-fa4377c9fdec",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77cbf55f-56cd-566f-9970-54a5a7849592",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6756eee3-97a7-5ce5-9506-bad0dbf69f9f",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.9 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.39-tuxcare.9"
    }
  ]
}