{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9d7ab2c5-fe4d-5728-a319-063f8d5ed8c6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.31-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5b30099a-d251-51d3-8864-425e73f0bbac",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03293f6b-d1a7-51a1-9849-55730c748952",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6df49045-5362-581d-988b-e698cf58e8d1",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:374d85a1-bc1b-50ea-af29-295eaf5a75f6",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a92eed4b-424a-5e0a-8507-723dab44e492",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2adf81ea-7934-52e0-8f40-a8564195ca27",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26058655-2d84-5022-8b18-72a956e8a8b2",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33fca7c5-f937-5a83-ba29-1f2556d60551",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:065186bc-2a49-592c-838c-ab53a6980b83",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d603553-b867-5fac-853b-ef248eb77598",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be9ad9c6-ff97-5304-8fb0-bf669cbb853c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f16af1-7143-55c4-9da3-3401bd5a1eb9",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.31-tuxcare.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ef0725-46d7-5c61-b65d-f2ab8217c355",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e7ddc25-7a36-5faa-86af-7376e50bf3ae",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efbdcd68-890c-56f4-8fd4-73a85d79e1c0",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc342f6-ad8d-5719-8448-c0ba325b68af",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71f814c6-b4fa-500d-ac32-8f4c39d62c7a",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4005f07c-8784-5d60-b075-74f3bf4dcfdc",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a381528c-d57f-5ea0-931f-fc643671884a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f5d9ebd-59cb-5542-92e4-6958ce96ebfb",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf8db75-f6e8-52b9-84ac-bb1d75b17d50",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc494423-9e43-5292-a292-afdfcbaad183",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257a179d-c261-5cba-9ce8-68522bf15034",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eac76521-077d-5811-a8ca-0c7db8e1b6c2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e57949-0fad-5a8b-bb9b-994b866276a7",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d25ef0c-7200-5d8d-9fa4-57821bf7f06d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cafe855-40e3-5bf4-a2ca-103a5f6c4d6d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f6ab2d5-fd65-5c4f-9b27-4d01fc903127",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51b3a520-7a82-5191-8fbf-5b402bdd7938",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fb108b-6dd9-59dc-a674-4a699433d6cc",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a84dddd7-5303-5764-8dfb-052855633be8",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b91ce6d-116c-5740-b700-3017a7013462",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eadb5b63-a3b9-5d8f-9192-cf8f0c548cf4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96ccd5c0-889f-5ab0-8172-a54d6324c0e7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15bb03f-0236-589c-95a4-0062aad6810f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17bc8afb-d82c-5c8c-8adb-1de437defa13",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92133a24-7f67-55d4-85b7-89e4dfe6d5a2",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f76b8bcf-c482-558f-b207-104cb575ec36",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.10"
    }
  ]
}