{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:efdf588c-8ace-51c0-a203-727fa16337a1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.37-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:90a67585-b37e-547e-abb0-b0ec9a90dba3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1afe047e-58e4-5d44-84b7-ee9676e1efef",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173a00bd-b4f6-5862-baf5-1f1c670b5dc9",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:752e0a99-36c1-5d9d-8bec-0e1cc91463f1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ae38632-4230-5d64-9d82-ab47308f26aa",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:367d230b-46be-56d5-a1b7-d24d925cc112",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d3654e-4e38-51ea-ac9c-2393f84922d3",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:359ec1f9-ca63-5250-994b-40f335fb46ff",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d840a38-4e11-5da5-bcd3-037f6d7a3c9a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d5781c9-6fce-5384-8d46-c4e9df127e35",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:821c2bf1-f942-5099-9e53-33d193f1d474",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfee0afe-ddac-53ed-9a9f-37459d89936d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b941814-8b01-5437-8970-3b57070df338",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdda5679-a1d9-5139-8b6a-28af447b8f17",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bdfab60-3862-5f79-aee0-b2bb843438de",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93725968-7a67-55b5-bcea-135091052fb3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8811d2a-4739-5f9b-aed1-cb1de13b108d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b37014-eca5-5db1-84c8-844ccdcfdd60",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c06ae563-93bd-58d8-b1d7-fdb9c2344300",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b00b86-3ce5-5ab9-b53f-ce1541baef71",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40eaaf6a-4284-5226-ae0f-5ad12ee5e3c2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ab06628-a3f4-5b05-906a-ddb9babec3aa",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff939f1f-0c1e-5a2b-8e35-2ef8a3d6d636",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55fe7c06-bddc-5776-b66d-c98279ffc3ce",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97643887-a6d1-5da2-a166-8b98e7de708a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62065e7b-71c8-5652-aa1a-85585c4d905f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5154b40-05c2-579e-80cd-5185b4849f34",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745b34fa-7d20-53e9-a6ff-913c2a6207ca",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc1c1856-618f-57bf-ba1b-2e4e5ba8f9ed",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff7a603b-0034-516c-afdb-84734e449990",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419d6f3d-85b4-5f95-b6e2-37145b7ea88a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1611b33b-c667-57fb-94b3-4866f4e11b85",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ab86f63-5c6f-5e49-a86f-0fa23fd813a4",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9645a4b-7a89-5a85-bef9-6a7db85d2719",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.9"
    }
  ]
}