{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6fbc6ee2-7fbc-511e-a67a-b4c84d1f4617",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "5.3.39-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6e5322de-8666-5ba5-a347-f465118f064e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbb5371f-2929-5722-b226-e5e4675130e5",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-test. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd37e21d-7810-5a6d-93db-e5c5ca69f557",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a88be8f5-9f6e-531d-b3ff-c115e277cc8c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa8480d7-ab7b-5aa1-a055-9c5fbadd5620",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a3e3412-af3e-5ae8-9dd4-17fa177e93b8",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef22b990-d9e3-5422-9924-a706861357ad",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c9b6a17-3980-5de8-8164-e91c227e0310",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-test 5.3.39-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b0f3b28-d822-5b2a-87b2-d4a13d9c099b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e1fbf0c-e7bc-53b7-98c4-4d8f2d1fc668",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc2657b0-4e3b-5fbc-b16b-ba44532c6817",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc644bfe-a852-5c29-85fa-ab4076c0cb18",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8f7dc5-7626-5273-8d38-c80606905bed",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d06d49fa-ce70-5295-9945-32b3f37f6729",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a80baeb3-70b1-5eee-bdbb-68a84256f66a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a41c2e-e76a-52f6-8f89-e9c396802b7d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d692eb98-2e41-5ade-b66c-78f4a4a96e3f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd4040c8-8a7b-525b-ba9f-09b864cefaee",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d84a4a4-c2ed-5e05-b26f-63d089b5b1fd",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-test. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31fc3c81-572f-563f-9692-b63136af9e72",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8dc7034-12b9-5cf1-bc0c-6b9640cf953f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92e26438-9d8a-5254-be63-a106693da12a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a39f89a8-6c3d-5dfb-bbe1-b352c5772b4f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:296bb263-59cf-5122-ab32-b7515578edf6",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4eb388c-8880-5f03-afc1-cf502c253c38",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07e58f17-ded0-5300-8445-c4ac840f90d2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e74dc75c-eaa4-50da-938a-d30a51df1a5c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0352c3d9-ea48-50af-8d65-aeb01b21d9df",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3b6a44-a809-5a0c-b296-c2edabbf35d8",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c0f65e8-a2a7-5f32-9529-4faba4146d8c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19895aa1-5a92-5133-9b8e-a30d6bd8b3b3",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d74c557-56f6-5121-bb1b-ed616bba55f0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b4fa742-4958-5db1-b82e-e6bcb42cd724",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.12 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@5.3.39-tuxcare.12"
    }
  ]
}