{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:04eedab6-7b7b-55c3-b98f-12aa2f42e378",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.27-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e2199ff8-7054-5fa8-a8d2-0ed5c9d065a2",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bbdee61-3bc2-5b2b-9b65-9e11a199becd",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:892bf90f-c372-52e6-8615-5d4275af79c3",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e922a8ec-005c-5e74-9b67-74f24da16f61",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:418600f2-4744-57b2-bd38-bd093ea1ea35",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c3211c5-6017-5dac-ae3a-68b4de3d65b7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:795966d2-5a81-5928-bb0c-9ea1850e7014",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:384b9d6f-bd9a-5d53-8344-118c896cac25",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5b8a219-491c-5890-a6ae-2f6acbd966b6",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00d3625-a9c7-54b4-98fa-72708fbfd69b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1305382d-f515-56e4-8489-554421cd0954",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d324e5d-2073-5f72-89c3-d48539c01995",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.27-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e8d5bb-3417-577d-bb7c-9d9b4af278ba",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d9a9d01-f63e-5dab-86c2-60534df4c0cd",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce28c5b3-64b8-5f12-a5b7-7d657c04e454",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e67974e-b2e5-53ef-be29-0dc619a05ed6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6dfb281-4aba-528f-a9ba-167770fdc725",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff5de4e9-f03a-54c7-bf33-ad710ff90d31",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c02febd-54e2-5bdc-9135-2a80b28b41ea",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:969d36fb-3b99-5f63-a38a-6aad579038a1",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ad0c08-12c8-5f06-b5f2-e52714d1b055",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d590989d-1edc-5746-84a0-05494625e90b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690f2076-ea3e-5fda-a310-ef92ffed41f6",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47246e66-b46a-5045-a241-14224c0f1078",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:351886a9-d7e3-53ff-a909-b78122b05b36",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1644773-a061-5f81-a2e7-814d18793198",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c913224e-051e-5efa-afb5-ae56f12c4430",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca62a0b6-c8d6-5818-9175-3c50c069bd6a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6de66d4f-3197-516c-9af1-211194bdeaa2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e12153e3-cab0-5a33-bcf3-a6a6aa91a907",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4f5128-bf43-51a7-8b84-ad2048700ae0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:458e97cd-8fbf-5dbf-ae1f-2620b27e7c54",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fcd292d-b4c3-52fd-aeb9-27b57d5bc2cf",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97b7d73-c6bd-5d4f-b47a-479905414af0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84069f44-0763-5aed-adaa-df9279dfd753",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c56862-3b47-5769-beb4-f628021eed10",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82fd0b51-fd78-5b58-9f03-4b5bfbd3d1b8",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9e8d7dd-b1f9-55c3-9761-56c6bd8f54c9",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.7 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.7"
    }
  ]
}