{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3628fc85-3a52-5ffb-b533-8d2641df19f8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring",
      "version": "5.3.37-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fd26f6fb-3d29-5086-ad31-41da577fd918",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:022e1dd1-2418-5b17-aa5d-24aabb43ba11",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c750131-3419-52f0-9223-7fde7cfd5a27",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c49ceb-eb40-5188-a7f3-ec7f94d156fc",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4acebccf-09e6-5e85-94a5-19fb93b390ee",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6038c02f-df49-5008-82c4-d265ed8a5c05",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33187684-da7e-5d2a-ac7d-f969db0d6323",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648df141-ef82-5c23-ab3c-1a3df669a339",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177e2610-bc6c-552f-a5ce-420f943832f1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3da76a44-22f4-57cc-aad5-205d53b2d4e2",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec9f82f1-b14b-51ab-8a2f-6c586db6f909",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ee45595-3f2b-5e57-a17b-031c4834757f",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8df1f95d-5ddb-5d40-8681-8868faa1b2dd",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d78105a5-8fa4-5b67-aa53-16b628cdf06f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57df3a3a-92d0-5304-b5f0-a2b82904de49",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f08b7926-78a5-52e0-9910-fdc075f1ea11",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e988a268-d0dc-5236-96b7-2be2b1b469f3",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:572f8fd7-5624-5157-b2ce-10a73b1b632a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b514d2d-90d4-5bb3-b247-a6f827b9cd8b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:376e7e21-9624-5cea-b3b0-01fe3e0ded38",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:932e472a-2bfc-5545-855e-7c916bbae3e6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4876ca85-989b-55b3-b449-af3899ce4ef4",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db0153ae-f087-5ea0-8541-d45f1af53ca3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a3dfbd-7c7e-5824-b715-4a69fef44956",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d358e535-4b07-5b01-9a04-54feb21885cc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f93eeb-df92-5699-a8b8-204e5a2c9704",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34493228-4bd0-5311-8741-f3c83f2c6529",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:383cc217-32a4-5352-ba89-36d829142045",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4560fe2-109e-5d81-a486-5df59a7175fe",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9aa8242-0730-52c2-aed5-171c72a605b8",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae41b367-d0a1-5857-8394-4a36e3b1b1e6",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc47b22d-de65-5811-a9b8-f6f2a0061db7",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43f7c7d5-59cc-5eea-b1bd-3b4d1c52edd2",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e63e20-3be6-5705-952b-f6b9200ededc",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.9"
    }
  ]
}