{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:baee9875-fce0-5b60-9cbb-b2c9c145d03d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.39-tuxcare.19",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:67d69227-cbf8-597f-bbf6-6a1c3183e21f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e36e85f5-f1a5-5be2-9445-80aaa114885e",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b133ec-21d8-572b-9a95-8075591b54e4",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6100deaf-d43e-510b-a690-ab6fb8ef60d9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6ba6ee-eedd-54b6-a567-870d1df8253e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc256756-0e11-552b-8874-de749d7bddb7",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ee7c739-a2f1-569a-9aef-4a783b8bb7de",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98d06de2-6c97-5af7-8d8f-88f38bcc41c9",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.39-tuxcare.19."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:962ddf23-4ecb-5c25-b5fb-270cdb241c4e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9cd4072-8177-566b-ba36-34062e6fba58",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c94ee24-9810-5ff3-9093-e6f14ec48bf3",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1cbd771-e6c1-59f9-bcd3-bff736e76ccc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a702d613-5731-5d4f-a80d-601bd83430d3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b36dcc1d-2bf3-5d27-96f2-1b90f2aae9f9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73d3b573-1470-5be6-8de2-e8fb998c6768",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a37b138-72f3-5c00-8983-e7389e9992cf",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d62be9-71bb-5e00-adf3-d8bd264fca07",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47039c62-d4a1-5814-9929-b6cc2c646929",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96457634-b662-5742-bc23-193b768fdd7a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6792cae6-a7ea-5bfc-97aa-04d995348e82",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ef782d8-39f9-51ab-8497-53ca1574041c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b05f780d-21ef-5a2c-a4ca-daa1a202c942",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9146ad2-6354-5ca1-9b39-f7d38c459b65",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0d4cfd1-81ba-5a31-871a-f7d196e24ea5",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fced631-c8e0-57c5-a8b5-99fedc5491d8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:124e4643-6ad8-576b-8c94-7dd19b9717fd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ad232e-bd55-59a4-813d-3562759b2f6f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a53c4f8-6158-5223-a262-7338182b7d9c",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9aa5033-9d49-53fe-be48-aeabb63a3862",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e78d446e-6759-53a6-be5b-f5b91ec8c689",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cff0e72a-6b56-5ad2-95a3-e16bc3708b17",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9130faf5-ae69-5e8d-870a-1dec1d4a4db0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a29dd44-2dd1-508b-b07b-4469936900d7",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c982207-26f6-5ff4-8c29-3bea02cab876",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.19"
    }
  ]
}