{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:db6e55fa-3d0e-52a6-a5f6-760227e55865",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring",
      "version": "5.3.29-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5d946190-9429-560e-8091-e0541cae9430",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d6ba61-202a-5fb4-a333-4f217116f8e5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:178d1646-d4ec-5199-be7b-0e1b942c7824",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0e2293c-11d9-59f6-8adf-adfc6aae888b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b723349-7433-57e5-8b88-76364039a2e9",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc621566-05ff-5813-8576-f1615003e8f4",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d20990d-276c-5685-adf8-d42306a38463",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e94ac49f-b995-5279-94c5-9010407bae67",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d700aeb-3793-52ee-beb6-387dfa34658f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3429af2d-03a7-52db-a890-83eba03db90c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6028301-1e13-5dae-9a47-770d2c799b43",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f261dadc-0780-5901-98f1-7742c41977d3",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring 5.3.29-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:452d790e-d286-504a-978e-73ccebe0508e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e14bfd13-b477-5d39-8d86-50d6992084e5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99664f79-0dc9-51b2-b197-0c488745c7c8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bd73713-5850-5679-af6c-dc0330f64b06",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f266a6ca-d08f-5933-8dfc-b3087f2f760c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edc112bf-5e2d-599e-9b0c-6defdc77a945",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bbacd07-d3af-50c3-9d44-a0c5975b6f97",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81dcb712-4105-5314-a8d4-3a40bf7242ed",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb7fa9c1-b1e1-5a75-9709-91c064515968",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c308cfac-de57-5dc5-84bd-5fba44c424ba",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:509635ea-c14a-5de7-b271-0648d8f9668f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.3 of org.springframework:spring. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28ccdc31-d55e-59ac-b81b-fb0f87bb0e0d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bec32b0-84ad-5ee3-823e-610f5db8302c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:756a7e6a-ced5-5132-a912-8a76e5ec6e3c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:999c878c-f1b4-5225-ab66-171de80fe49a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a340be-3c16-5799-b9df-2837f790408f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b66a97b-85b1-55f5-8b5d-8214bb65c819",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9b7fabc-bd91-50e5-8214-efde73e9f022",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828c2084-32e7-505e-89da-5bcd428a496c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03c8ee08-6ab9-5d0f-9dcd-4e7b0a48d290",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef534977-799c-5cc1-83f2-f6cff0413ee2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e4c457a-6b67-5a31-a862-697d3e706311",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a2509cd-31b7-53fa-bc91-8294827d915e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5655a457-270a-5817-9d2a-f7c197692b55",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5434bf48-c4b0-584d-b5d0-4d1306c49f98",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.3 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.29-tuxcare.3"
    }
  ]
}