{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ea63a2b2-095b-579f-bc19-4204be635518",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.39-tuxcare.18",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5991ae65-0d38-5663-aada-327dc0f9a9b8",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1993212-5cd8-59bd-9e24-67a8b2b38e05",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a6ab82-525d-5e0b-8d12-907558b698a5",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:841a1314-f818-57d3-96fa-e963beacf7e9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6941a4d6-1093-5ad4-9619-1d84fa3d40a0",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d4a3339-265e-59d3-a6b3-786a8bdb55ca",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dda18c80-cefe-5853-8137-f33074e03c31",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9232c472-d0e5-594a-b371-44071a641acb",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.39-tuxcare.18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d61d0f1-0d90-5770-a879-fecc7637581f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df62fa4d-7d95-5a22-b0a6-d4d87f8a4698",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1785d6fe-f952-5835-9b26-3aa6e2d6485b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4afca46-3dac-5a10-8286-8780b3a5866a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f7f00bf-4969-5428-8af1-85af9fcce6a4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602d557d-9ce2-5ac5-beea-8123e61b1f06",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf42aed-5b9e-51d9-9eb0-503e913c4619",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03d2ddba-b442-5de4-a0b3-789579534bac",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:983d01f4-965b-51a9-b537-a8bb169f755a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:209f08dc-3d87-5c33-bf03-2cea794e7212",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70e18b94-13e3-5921-8f19-ce8505340273",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01833fcf-ee80-5a9a-a851-de61a63fd236",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:743948ce-7763-5380-9608-befdb57d2b17",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff9b77b-0238-54d1-a69f-92a427de6dc5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c506b2-b5c6-51cb-bcbb-3c14b6fffcef",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58bbff70-653c-5119-a810-aa90fa0332f3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b27754bd-e7b2-57b2-9955-50ef594d0ea1",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cceb2d-29cb-5fb5-9627-609caa086922",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b821095-7baa-5e20-abb7-660c1f8cb5ab",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:448d2d31-f118-5aff-842a-040f98ebda1d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9902cb5c-5656-5c31-a80c-47a9c25add5f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15284923-a0e6-5913-a3a3-77743fac0f4a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec95212d-2c3d-5c76-8a04-e2de45345026",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15bb1d86-3876-5f32-bbf5-d791e696b1c8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd4605fa-3cb9-5127-a1c0-101ada716975",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e309181d-cc7f-583d-9a73-9688d8f25fcb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.18 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.18"
    }
  ]
}