{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5a4e6d76-cde0-5758-ab3b-7a6d185d8a70",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.39.tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f8f373ee-5312-5f69-bd51-b5ed3a991075",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9ccd6a-d83a-58a2-a284-6b3fa33954fa",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3679bc5-2efe-5e6f-a827-a1d20fd45a50",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6685853-3bbe-52f4-94ec-ac67587feb87",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6c446f-abe2-5f0e-b3d1-56c1b58bb9dc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca9a027-d2b6-529f-bbba-f3943f0f95b3",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e68737d-737a-53fb-9c63-0701fefd2788",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0549a045-f650-55b4-892c-ee9d286b921e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.39.tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bef593c5-3729-53e6-adde-0f1caf416e19",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93cc4133-c166-5f01-9ed1-593080e4f4c7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0281ceb1-946b-5ba2-86ee-ed12c3711bba",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f301738-7dd4-5dad-b884-352337d3c7fa",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61106caf-59fb-52f6-8179-9182fc0b3c4c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af23ef2f-d337-5bde-8f7f-6bc7eca52000",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a324f665-169f-57b0-a95e-ae357939675b",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e54f23d-a10e-5cc3-aa75-4b457e5f0afd",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7aea650-a903-5b27-b949-0a202fbc5068",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:563ee252-1e07-5a36-a1eb-2d97c5687c40",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9eef300-b4b9-56f6-9bee-e251b086c8c4",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2622824-b2a0-5439-99cc-0d8572536f5b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaed964d-7b9e-5c89-8d88-46d2d5135f30",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:813b6f6f-68dd-5602-a2ef-560e0d052673",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7cbca9e-9523-558a-aadb-a505b7e22cc8",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87dca32b-d402-5de5-a558-b96de2eb1756",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eaa1ec9-daec-5d43-a039-217118a46e6d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f37b3b-8a36-597e-9b6f-17188596ea71",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc589139-9b67-51cb-9367-b443207c2234",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1d40290-6ab4-5c7a-bd25-0bee4f1eb121",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:604899ec-2240-5287-82ec-6b507025ad3b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38131bfe-7c27-596f-a3ca-4fb13e53a860",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc9426dd-a7ac-5556-a888-54fb05cd6f33",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c588608-47ce-5469-985b-ac4e8f77c96f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eec60821-c2b5-5f14-9ddb-3140a9bf2515",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39.tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39.tuxcare.5"
    }
  ]
}