{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:10f5465a-e33f-5182-a675-d8b710a6a2d5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.30-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8a3efc99-1eb5-56c2-97fb-a6b2e9b6cc23",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e325f67-33ea-54bc-a224-6f2cfd17081c",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:015e1c64-bb29-52cf-aed9-a5932d01e471",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:653e4624-c2be-5e65-b036-9d2b4c8ae61f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:248f94c9-8a16-5dd1-bc79-4d15b9872f5f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eefc46c2-a112-53ac-8935-9d5330982d30",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:583f83f3-7e57-56eb-a3d8-aba7cce26188",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293dd77f-c023-50a7-8314-6e6928090630",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2751fee-1357-5c93-b8bf-17c328612914",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ed4465a-b283-5e09-a9c6-b9b332f02115",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ff205b3-5900-5b7a-a71a-aa3854822d8d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9713e35-ffbf-5ae3-9df0-f69b926be04a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa21805d-00b8-5ae5-95d2-0a4296bb3c39",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a9db14-411b-5a7e-bcc8-b4e421f94c6e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e59b60-5d6c-5fe0-a869-085b02257af4",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411c9fd2-7a3c-5d9c-8355-c88702670ebc",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc10242b-ca43-55c5-801f-0fa071d50d22",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:880d4689-0426-5d51-ab24-2f86c68acf31",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3f5ccff-ab87-554a-9610-2234ef2bac86",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afe57d5a-449c-509c-bed9-7921fa487e9f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d7065c5-1d1b-5e4e-9ba7-1415bea7fc6b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12201722-881c-5640-96b7-6a6d63803a05",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaf535b6-f0f3-5916-a813-4bdc8f08dadb",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89fd22b7-deed-5a01-ab1e-0ee9d29cb7cb",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a31e616-d93f-587d-aecf-a496409116ed",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c1de6c2-94ac-50e0-b0e3-80252a683285",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:185befd6-e3e2-5f97-a3b6-7d92757789e6",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c8b162b-aaae-5a78-b8e3-74dbb87e4cc3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc497f0-2f2c-529e-9df6-cab8b7004d78",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6538e03-15f3-5a29-948f-d6f29b1ced0e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07dce6c5-8c88-5778-841f-77d04c1a0a05",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd2a2fe2-090f-51d8-b074-52aacbaa0c10",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a82853c-b40a-5ba1-8f4d-3c935a1b369f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de26486b-268b-50de-bf9a-cf27c92bf32d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4ad2581-4281-59d8-a3e9-1b5a221069cb",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffa12377-c0a7-5869-95a8-547e1fb01ad4",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6e82e00-aabe-53e8-b6fd-4e34f0d0d8a8",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.6"
    }
  ]
}