{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7c1a60ad-1000-5477-bbd5-47413f6b4075",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.30-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0fb384a3-54fd-54e1-a4eb-3e311d0b5262",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3fb240a-e77b-5d57-93b1-2b75e258fc3f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7505d7a5-f416-5528-aa70-fc5cbfcd3896",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ce7a8aa-40f4-501f-9fcb-90c26100761b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f9efc0-2b73-50c3-90c7-34d69918b16b",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a60d1f-db26-510c-81b4-67f186b673fa",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4cf022-83b8-5fcf-b1e6-34628641f3e1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cb8ea2-e362-5f36-9da6-e7453d261964",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15acf9e5-697d-525c-9eee-cffbe5ed836b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e50dea8e-8fe3-5b40-a902-3581f8c4a3da",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be598fc3-fd3f-5a58-a33e-6de8487b9ce3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94de4352-2b98-56c6-94f7-6b18e75b285c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87b17f25-e2d5-55f6-b121-d18b48f600c8",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:767b871a-b9cc-5ebd-9c84-a3e36ca5271b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2e682bd-ce72-52ec-bef2-43fbe2ae3dc8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:374fbb60-1b98-5cf2-b068-da4778176dae",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c190036-b83a-5867-a110-f5653fa0f802",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30cbf243-afe1-571d-a34d-2e53ff3bcccc",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe8caca-6a3d-5ddd-b28f-c8eb422dfa44",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfb81b65-adca-52fd-810c-4786a4c07c03",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02e26ddc-2e7b-5763-b1e4-072b4b87bccd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28507e25-3bdc-57a8-8ba5-0cfc81dc5067",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d84ff67-adfb-51c3-a479-0fa12e4677ad",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a32e3ffd-5927-5017-b9ce-796505334558",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eb263aa-7585-523b-ad32-fa06a5c556f1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1f4eb81-b61c-5167-882e-95ceaf83d9cb",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b765a988-ed01-5412-b0b0-5eb460117464",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:158f2888-8222-5baa-81af-969a08e7f9c2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5685a4ef-9e42-52e0-bb69-6542b7ed764a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d59e9e8a-535a-57b7-a90d-d7e0b925f1bc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e10ecf7d-69aa-5e9c-a7a4-dff4aff173be",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a80579-8fbf-5d28-a339-0330ff1d81cf",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cdf90e1-ba5f-5123-a2d3-3f2f5070773b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b2de373-3218-5ea1-8edc-0ca1df4cd0c3",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c20693-2a9d-519d-8600-1e536c78089d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a97a31a8-8798-50be-a072-6606625ee349",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59104a45-94ae-51e0-b6aa-be2347e40157",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.30-tuxcare.6"
    }
  ]
}