{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2b0ddbe1-ba77-57eb-910d-dc5377afa73f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.39-tuxcare.19",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2fde76f8-4571-5257-9341-88dd65bebf00",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a503efe-706a-51a5-a528-5d5180ecab9a",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ee31d6-1d48-57b1-bfc8-1593220dfa48",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1138567-2f2d-5c41-8837-0190022513f6",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae8cd8e4-7d93-5db8-b7a1-0afea1b28218",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:300aafff-dc10-5e90-bed9-9137c88034af",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f3d4e1-7142-5d75-afae-56d77299eed9",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc5591b-2949-5b2c-9ecd-03e60cb669c9",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.39-tuxcare.19."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fabf2d4a-23b1-59d9-b030-af14dc3aaf22",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce79d60b-c645-5203-92e4-f7b63bdc35ab",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef11e3fc-1ef8-5da8-91fa-0fee383a142d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12590cd9-605b-5a7c-88ac-63a748b83422",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92feba86-3414-5da4-b3f8-5a23648bacaa",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786f53ba-9323-53c2-8288-4a2c13b17bb1",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:795c66ea-32f9-53a1-b944-2bff3e25a87e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fad3655-0a1c-5251-9ba9-696bb6dd750c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01770150-ef68-53f7-8733-ea75c2bdd7a0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d1ba7cf-ac5f-546b-8e01-6930ef6db505",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51c646a3-2e3b-5fe3-964b-83d7c3a44dde",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e01a10e3-29c8-5d7d-a41e-026d97ded045",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba4f068-b490-50cb-acda-c5d5f28ac544",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be665453-b22a-53a7-b114-f6474c7c53e1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35160921-0e56-53b4-9e36-f472a46de8aa",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15dfbfcf-6b35-5d26-9ad4-f7368fe1e48f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2679db7-85f5-598c-ad27-fbb0c81ac671",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74fb5e46-0f53-5eab-ae6a-61da9203becd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3d4016-737b-5730-bb68-0f374e8d05d1",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd2a7783-9398-5c32-ac42-465185c01c74",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8107ae7-6ac7-523a-bae5-9c45a49e711f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b8843a-3770-580a-97bc-03e973190a86",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47cbf580-2d17-52cf-9d26-4da086b0fa97",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a065a3fd-afb6-5382-b21d-9877e0224a60",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:418c8fef-bdba-5b6f-91b4-940babaf7f48",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7af318a-d844-5672-9a08-07bca7ff5b6e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.19"
    }
  ]
}