{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7b4b9732-b889-5487-b78a-1e0404505018",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "5.3.39-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:04a6b147-252e-5190-88c6-3fe438cde6ee",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee6eb55-5ab8-5bf8-9630-f3dcd9b543de",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.9 of org.springframework:spring-web. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f90c853-f88c-5f99-bf5e-0b2ded24a318",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14b10aa6-de13-57b7-b1ed-429f54f064a8",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:719156e2-a469-5274-9f90-d99a69e807b2",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d47c0f-db79-54b2-8060-4053350bfb32",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea091be1-6011-5a10-bfdd-46afab8c4d85",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a353c0-79fe-5d84-8fe3-e8864bb4e8a2",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-web 5.3.39-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef72b198-710c-5e80-b981-831c7df0c098",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062de74f-d329-572c-8c89-2789f36f06a7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9789985b-fce7-5af7-a938-501e23e700bc",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de57f470-f858-55a6-8763-8d74ddc61281",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90882811-121a-5301-9cc6-a4d2f984a2e3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f92c6825-41fb-5362-a886-d418d71d1d90",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c775150-baa3-524d-be1d-84f4c64e621c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dd57b91-b82e-5104-b5d4-84ad545b4aac",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82cd67ef-e5e5-51a1-bca1-40efa89af5a3",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d3c57a-d87b-513e-8b7c-ac20fdcb538b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c40d6bd3-1ff4-5048-81fc-25dac67348eb",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.9 of org.springframework:spring-web. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6d64ca3-44f4-5f97-9b57-61c4839dd1c1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3479e5bf-9d05-5964-8045-91ae103fcd1f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:594674ac-1181-5f4b-9250-523f6db39207",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7279fb33-eb14-586e-8524-5b74457729fe",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a679208-9901-542b-b217-f59a9c09426b",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe6a28f-f6de-5221-a433-ac932b170c7a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20e4f992-909f-5b55-a54a-28ccc873f505",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d03dc04-8376-5866-8852-a5f1b6df6790",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb44a54e-d614-5946-bb57-55df9dc7953c",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37069767-8e3b-5852-be95-656544e62d29",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ccfebc-bdd5-5b6b-bd1a-e633e8f27c32",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9262743-d321-50c6-aeba-d5398d1dce53",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb3923b8-fef3-5a6f-8c2e-6174008252cf",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60de6703-0b09-5c75-ad42-d8cf8ff4dfee",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.39-tuxcare.9"
    }
  ]
}