{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:466eb181-acb7-5ea6-88bd-e0cdfb0e95fb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.30-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8a5c30e0-3b98-5b67-8c44-acf6c445d276",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:817ac081-ae1f-5c50-9daa-e958aabc5dc9",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64bd159b-2ef0-5a5d-8e93-269e3fb6fe9c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:897693b7-6e05-53da-a7dd-b768802958ed",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:329e7643-841f-52b4-ab8e-fe1a1b4dc93c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c006df7-d1fd-5ff6-ae1c-b2df86427d2a",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1493871-9ce4-5ee9-916d-390bcce3aa0c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562e7a75-0734-52b7-8192-a7a6a582fd43",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:137545e1-121a-5cb3-b4d5-5f0531e724ae",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8842b11e-fed7-5c3f-8697-2f85377d888f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c1d811-dbb7-5d47-a97e-955bff8e3c4a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abbac7eb-93e7-54b7-add2-a73df3d95cfe",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d0308f-b7ad-5586-a8d5-04e76c25abed",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68a9e87e-ccce-5915-8614-2a76dd885893",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0044fe1c-383e-50dd-9a02-19eb11b625d0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d62f903-bab8-5b09-9d4e-ae7d43401b11",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea77cea-bdba-5692-9889-8954bf20c648",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bf03019-4f20-537d-88a1-ada8ec4b5abc",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7d0721-c7f4-5b55-b968-9dbfc7a5fae4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3ad8a68-f30e-598d-9a06-31b1a5042d27",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad031d83-c784-5154-9906-2f79aed41c22",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:632b9cc1-2ad9-5f1f-a46d-d4971ef112bc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d99b5e-db5d-5a83-b52e-372a06c462d0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb4113db-71e1-5eac-9ea0-eab604910380",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:298dcb4b-abac-5244-b94c-bf7131b156e5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49ff8a7-a097-51ea-ae26-673c44612a01",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ce36f8-b132-50e1-beeb-8a18abfa07a7",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0538ac-87f8-5117-b7cb-ad27b2b54bf3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5da119-292f-5865-a3f6-f350f37289af",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:380520fc-2e1c-5199-912e-c8a005ebec4a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:021c03de-682f-5426-a83a-3b490ffbcf19",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8c07d9-e263-591f-8557-73ce83d628de",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a30a0e5-51fb-52a2-8829-222f96b2683b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c5ce6f0-f9c6-5e1f-a00f-46a475ec1d2d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f812510-3a34-55cf-bc29-c8c8184752bd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adc2c6e-146c-5694-b303-fb0681aa59ef",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56908cf8-fa15-5150-973e-2317920f5bd5",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.5"
    }
  ]
}