{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:95b9456d-c048-506d-b854-024ecbe1a127",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9",
      "version": "4.3.30.RELEASE-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0f05833d-fb6c-533a-bae1-016991f999e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:60231c11-9273-5e35-be1a-2418565d01f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:32253bf9-d8d4-57ad-b4fa-c1e9f7c8b2bc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6de3620c-febe-5a6f-ba91-03ee0c9a64da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0e256dce-c67a-5675-8983-29072acb837d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2cf9188a-776b-51e0-b1c0-acf6e8c33e77",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5fd3b220-50c4-5aa3-a7b6-6decde642895",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:43c452f1-b50f-5542-ac98-0dccc77116f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8a02a4d3-d155-5739-9617-4d8de65beb1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7f2d5495-19ac-52cc-8b38-e53b0c6f34d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6e1811e0-8417-57bf-8b01-86eb528f22b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f957b3ed-d60f-5c85-af4e-afa958c52f3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9095bbbe-6fdb-5a24-a769-181ce2f15b82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c05cc23e-a8c1-52f8-838a-322f620514fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bff5b98d-5d04-5247-bc03-082cd947060e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4e1c19aa-c98f-582e-9cfa-0ffac3e9cdb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dfed57c7-3df3-5e34-a73f-09e9e21a82d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b2d6bdf3-b90b-52aa-8c95-593d2ebecc23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:47bab576-f995-5bec-814e-3ad21cdab8b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6e6aa28e-fb8f-5009-8e35-232c4615641c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:33c9501a-85f1-5bde-b7cc-8264019b5c20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b391b0c2-f728-5aee-a843-1f7f6ced2096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:79f4b4d4-56dc-5a71-9481-6e7a6269d0dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fedf95f1-06a0-5852-a9d2-3a469e92766e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2673efaa-3db2-5477-98f4-95fe281c3561",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:45e025f0-8456-5cb4-9c8c-192403c65651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6b8e3e45-9a76-59fc-a35b-1792e0fd9da5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1443f47c-3c32-574f-8341-093110fb145d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d5dc9764-8058-5e62-901d-629afd99fb57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c9ec07c7-d8fd-58d9-bb5c-111ca795bae0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:593a60cb-c298-5462-933a-3c22e8b6cf84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:66aa159a-7399-50a5-b400-4bcce5cc2d6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:067e6f1a-9468-5d7f-b755-6fb01fea144a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:90346093-3d6e-55e0-a5a9-f41ce1cc586f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:586d59bd-3d65-5479-8eba-a09c26c10e91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:908d7ced-9d3f-50c4-a5d8-6029ef261efc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:665d9776-afd8-566a-9239-a0185aa819dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8137a956-3eaf-5c1b-89c3-d8a31a864e18",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f629c313-a263-50b4-bec5-75ca7b325003",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:493ca202-2b0e-59d5-a3bd-e3a19e3f05a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b1a6ab94-0f08-54ae-857c-97cc61236b88",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d93a61d1-3df4-5497-bbb5-4082938af807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fff1e13d-d932-512c-b370-93f0a5f123be",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a179b365-5a58-5e11-bf6d-1e18ff62057d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:789f3eb7-7e10-550d-b2f4-8ab4b5216398",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3d0baee0-b330-5019-aa02-4e6ebaf7c848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:51d3fd19-d6eb-5e83-8467-689cb85f1a69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:aa3a6aec-365b-5a8d-bac5-5b24ee2cd567",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6d90ca28-0c32-5c76-8dcd-ee530b1cdf02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2b27c9c1-0fd1-52a2-923c-d248d185a346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:50cff49e-0af4-5d11-9a81-79ff3c83b615",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fd3a08c0-8a99-5375-806c-558e37e45f84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ca2d5163-086e-59e0-9bd8-4fed92358716",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.9"
    }
  ]
}