{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fbcac93e-4e90-5166-bc8b-ca8a8ddbfe2c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "4.3.30.RELEASE-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c52a2a13-539d-59bd-984f-a577a8642349",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5efb34cd-6b21-5930-8b28-bc7887620ab6",
      "id": "CVE-2020-5397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5954d9ba-9bf7-5bc6-b3bd-895564fd8e8d",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ab925a-5c44-5d8a-b5c4-886ee4bcb81f",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f19ec914-e01c-54a8-9cd8-fa70c19bd4cf",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9227a429-1c47-5346-8ca2-19fcfd11c1bd",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1f2ddce-ebe7-52e2-9954-eaa73293758c",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c90c86-7d8d-5a88-a177-5abc8c65b566",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c408c21-1c37-5c67-9869-eca008f4a8dd",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba84fe6b-2632-5fbb-aa43-702107ca7273",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32adbdcf-7fb0-5859-a3a0-b00f8b993a24",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad1ef0b3-f75a-5c0b-80de-4ae249739736",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2866c9e6-b7d4-5fe9-becd-295a9efde98c",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c9e1b17-7fc1-5e7a-9207-0046b9dd8a7c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da58c638-9d38-5c4c-9891-d27419997cc7",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:440ae5f9-0298-5770-aa31-f3b2b8cc7ec0",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73bf0edc-f3b1-5846-8cd4-e02a0a327478",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed7a94e1-91cd-5113-a6b6-a6d16836df5c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e2c1e3c-bceb-56c8-8bf1-0f624590549e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37676191-8fbe-578c-bca5-7e9b2e8dacab",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8d3cbb-736b-5094-822a-a27e8f533a6d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a0f685-b69d-530f-ab3b-3a206109d005",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1870e3-3b83-5246-97d7-01f8749339c1",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a20e650-c917-52a9-a759-371760bb5e6e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e71e6602-43b5-5e22-a59c-9016324e57a8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7fc287f-7b3a-501e-8c55-af5c06586601",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ab4d39-0eaf-541f-9c34-3be3c55e57bc",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8acc417b-050c-563c-919a-64209ca7777b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18472282-f80b-5a64-b1cc-8d21a7329a38",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae7683ae-fa40-5bed-a2e2-cd98b5da8d85",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7def8c5a-ec74-5527-9f6c-6f9164a67ad7",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c2d8a9-1164-5001-9d24-a0563673a05e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c0a42b-4bae-5277-be8a-40619eac5041",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e25cb2-29ce-534e-ac6d-1364aacb294d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa0249d-0d72-5673-b857-97e4b4b5c995",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31fedce0-fed3-5dd2-a2e8-41dedc423f72",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:446bb3ca-10b3-537c-9a56-8ddc003d065b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5602b725-bd1b-5d03-a0b5-318e359ed6b2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c447807-9d12-507d-a2ae-224157343b99",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96b81b73-5e1c-5003-ba22-98a33470c276",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad81e5c-21ae-569f-b6e2-956d26a0c3b8",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:061e6fab-a7af-5875-9701-1277f56f8572",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE-tuxcare.4"
    }
  ]
}