{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:70e9cd90-3d43-5783-a478-33b3b33e184c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.27-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4cb2223a-36e9-544f-8b08-b5d2b409cd4f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f498419d-18c5-51e8-9352-aaeb801b8a02",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a3aad9a-9735-5621-96d1-840918304448",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd5357ce-5156-5634-ac07-be8e074e9db8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba53e59-3c86-58cb-ac0d-620d960bd207",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67d80a9d-06cb-5f02-bde4-a85ca3f65731",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25a49b47-5e5b-574e-b08e-f333e91c8bd0",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3f423e-fce0-5329-90fd-00e45e4fc2c2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:129ca7a9-09db-5097-b5ec-1260d733c02a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e6627e-d38f-59b3-a708-11765820eda5",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8456b9d5-a68f-5771-a2d4-d59d99d51670",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdb11a3f-2898-5cfd-8c25-021cea1a442e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.27-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52855363-97ce-548d-8ed0-5f3e27856dfc",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3147b95-f322-5e73-8e7c-ce48f1c26575",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9147537-4e64-5ff5-a690-625b0de6d4a6",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:849a7f2f-732a-5c0a-8aac-8efc23bfb122",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc3d633-0170-58e8-89cc-b9c9883df66d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f82d60e-ac9c-5574-9cff-fe61e7295c96",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bccdf4f-cada-59eb-9f51-239458901c35",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5240abd8-476a-5a37-92e2-fbae9b8ef201",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c994f9-f2d4-518f-b6dc-4f2d673fbecc",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92a2dbfe-4ab9-5824-a2e9-d657b3030254",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ed4f095-65d6-5733-9d3a-44b0fdc2b2db",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31596925-3ce3-5bab-a7cc-bf641cf5c33a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d930410f-9246-523f-82e3-965e89692a7f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:855beed6-70c5-57fb-8315-6f3aa9b1c073",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a735d8-e7da-57ce-a05f-9a16bd5e23dd",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a026a8ee-2893-5ecd-b530-988bd5ccbc8c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4f57c6-a826-5a3a-80b8-efc9a90e63e1",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:402a8bb4-76a4-5854-93eb-707c98ae652e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:349a248f-0cf8-5adc-8ab1-a96bc296d215",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da052b4-3e04-5e8d-ab01-b02f49c15710",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e229f07a-05b8-5c0b-89b8-5da3d840988c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f159fca9-991c-5a81-a459-77298950f4fb",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da306d1b-14e5-5c81-97f9-71538bec36e8",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1bc5705-79d8-58f6-8101-a22891b472e6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79506bf7-1c87-5f6f-ac80-364e5b4cd87d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.5"
    }
  ]
}