{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e2d1057e-8e08-5562-b496-462703b77a8b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.24-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1191d530-3b47-555e-8021-e649eeda32c3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b5493a-5ce1-577c-a93b-d444455e4d20",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c054da-3b2b-5f2e-a591-7ba9cf6be739",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3c3a40a-eece-5172-86e6-8436b7237f07",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b77ed404-eb8c-5428-b483-b6cf5e6d0bb7",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0f7b577-04e5-55d6-8659-f23564e9c41b",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb9c83c-a849-519f-acb7-ab1d883ed579",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0339e7b9-f4aa-56eb-aca0-9a2f15928b7b",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d54b22dd-a607-5150-a2a6-09d969f05dd9",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34656e06-c693-55e9-aa62-c75ac1bca9a3",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a54cb48f-1474-5723-9ce5-6ebbd9bd2dca",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4f17dd-dd1a-5491-a228-b2eb89f77730",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3ff620a-d1d3-501f-99d4-886fa3208f4c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dae4d35-8dba-5dbb-bbcc-82c13d1be0e1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7e2bb5-a133-592c-b886-45ded1a19fe3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d62d8c5f-3e37-54ca-a867-a64cf437bb0e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3e5fb57-d19a-5ec4-b0b2-078f919d1553",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e17ab5-b7a8-5b59-859f-8ea9da2a9c30",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff1159b4-9306-55e0-a941-d932da91e4e5",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14937889-5462-5dd1-825f-c762ec0ef246",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:297de02f-45b1-5163-ae83-e22e8857ba49",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:732e5f1d-bada-54e3-b948-7c28abcbcee2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9deb5f3b-2836-5dba-88db-38a129fa99db",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:450f1a12-b401-525b-8ff8-e1a1e0769480",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f2e6025-50fc-5555-8386-be7be7b6c06c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b8159b8-4bca-58f9-9d82-70288a18efcb",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f83ed271-7c5a-511c-b9d8-d1b0bb7091ce",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea436d7-00db-56be-8758-839c7942d885",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82b2301-0efe-5625-9a36-0510482b55f4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b83eb356-edba-500e-9f5d-8fb77fd6e721",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd4b12e-8be1-5afc-b5fc-115bf40b02ad",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5f4c4c6-45ce-5cb2-92e0-6ac3008e73e4",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7197829-959f-5973-a056-8038e15156d3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f67fd940-2fca-5adb-9900-9779a1399e03",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dca4dc3-e587-5330-86f7-91dddfa46a51",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce913809-9ceb-5fda-80f7-4462e7ac14cd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4b19ba-8e46-57e7-bb19-6f6cddf5233a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611e44a3-6f2f-5a68-8187-bee658865e6e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42166207-8032-56bf-9135-0bb44fdfab88",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d83ee103-19ac-557f-b955-9608aed844f5",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.24-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.24-tuxcare.5"
    }
  ]
}