{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:63cd60c4-2052-57fe-af32-681d818392fb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.27-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:01e94688-7aa1-557f-bb0e-73dacf868fdd",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2701024-7842-54f7-9d57-8ab22f5ec1ee",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096339b7-8fcf-5530-8c88-bf4ca26a8fdf",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ee182a-08a7-512d-8db2-3571d8aa26cd",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8603c0-c47b-50f8-aab2-8e7ab55e0019",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45bb3a84-2fa7-5b46-b010-54ba9eb6657c",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccc77cc6-1ca7-56ee-8949-5b738584fcbb",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c80818f-170b-54ee-a68e-b48bd969ed16",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca70b5f2-f3a5-5625-9f45-833a9fbb9b8f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c8da851-ef9d-5d3e-82a4-77f4a47fa79d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfd08fda-7359-568b-85be-226577e2078d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5be7cd42-043d-565a-9afd-4ce964a09d5b",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.27-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36ab4bc8-ba81-5d21-87f9-0862c07c439b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e2f2797-6152-5a71-a443-9c1d9a0de551",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f438500-5e06-545d-a1ed-8418e492951e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c67a1a-2796-59c0-95df-5f1698444157",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d05d0e-7c28-5ac8-b948-637903654fa1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21077539-135a-539d-abe1-27e0bb4280b9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5db5d8f-983a-5815-ba11-03d7e708e685",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35f125c-893c-56a3-badb-2872be64582f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88f72bc4-bece-5fb9-9b89-ac95221d5a2f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5cdcf75-2141-5686-a7a8-a6bea418a6cd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac7629c-590f-581d-8284-f5d6253a5b39",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d23f991-84cf-5013-9a3d-47e866f7cbb7",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb0546e-891c-5c2a-838f-88280067043e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d266c2ca-531b-5b99-9918-89cb46c21563",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13f503c7-cb0d-5bec-9e3a-e504269dc83f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e174d93-2510-50a0-a9bf-a0a4125aa6ce",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4267c626-03bb-5bb2-8f4e-914161929a8c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17bd83c4-8aad-5a01-bce5-c397bdb224df",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dca6865-fe99-5bae-bdbf-fc9a8e975dc6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f8e005d-3db1-5ec6-a19e-bbe7f8ac79c4",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e56c132-186c-535a-9b7f-a954fb4893b9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245e377e-f55f-552c-8dc4-549e10ba93d8",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:207a9c1a-2571-5947-aa91-7fae23c8c72a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9510d18-02cd-59c3-b6a2-8dd2e4bea462",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fef8e12-a18a-57b8-b87f-63082d360b6a",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d074781-ec14-5aeb-8d06-cde9a7246089",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.27-tuxcare.7"
    }
  ]
}