{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ed8e9c87-53e4-5bf5-bcc7-402b49ac7d0b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.37-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5b0af9ef-9685-5570-915c-d02881d14fe2",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f92c069-70c1-58f8-9ea8-a959cbdcaf75",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1854c82c-bdd6-5eab-bd64-6cfd6c34ca9e",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175fed0d-26cd-51cb-bc5c-31ec82d10192",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2892f1dd-af6f-5947-8786-1debcae0ca71",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4273f965-2e1b-568e-8bf5-5c796a889310",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bebe397-a044-5a88-913a-c033e68953ca",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce9e3d4a-d31b-522b-a30c-4cbc5c14fa3d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b96d815-c4b2-5bb2-b6be-6243e276ff4c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd846ef9-0297-50b1-8320-212215669ab1",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3112f0e-9a33-59b0-bccf-54f3eb2477f5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8910a3da-a6cf-585b-adfb-55f318d52f76",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e02fb06-c97a-544d-9cd9-e4d02b019b15",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e3bb3a-54ca-58d8-99cd-dce3075be4bd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:148b12b9-841c-5f2b-8bcb-72bb06146d3d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a2ae10-060b-58b7-9335-971d03b0b8ce",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465a3f6a-3f68-5689-b087-da311b080d65",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78f4eeb2-f10d-5d59-beb9-ce84bf2dd066",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15479321-433a-53ad-a716-1421b4a80111",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89d49d97-c248-5309-9b94-b5fae9c5796e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d954280-ea8e-5f20-9354-b959e79fb6e1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36867c4b-92cf-56fd-bdac-d6472d764593",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e23023a-9ef0-5331-ad3d-690a9a32a5ad",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30464112-79c2-597a-88b3-e2cb0b10ee10",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ffe2088-37b0-59dd-8cf9-0be478813be0",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:593f2a54-0da0-5e42-b7bf-ff52f55a58fe",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43fcb5a2-2657-509a-adea-b9b60e766995",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f677fd41-cae0-50a2-8361-19b294b612ea",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-beans. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d468ef25-0c97-52b2-9d12-70791be3a860",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:423e199e-dc79-55f2-aa30-69b10c23bc75",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56bd3824-7c40-5050-b181-4c8cf1bbf486",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2df0da61-b028-5e11-9344-c98e062e53ff",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a4623a-b777-57d5-8a33-31cb706d2358",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-beans. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c674c735-cd97-57df-9a4b-276ae7c98998",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f98bbc9-9b85-50f1-b982-69c57b7fb448",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bda005b-2ed4-535c-bbf2-268d436dbea8",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a9eb30f-ef16-5691-8436-1d81b128e00c",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9e9d7db-0c33-5629-b685-83d1b519298e",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecdb95be-4d2f-5a49-bbc2-f9477544930d",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b0cbd3f-77f6-5fe8-aff1-58b98494c4dd",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dac67842-e3b1-5093-ae70-d432b029603e",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8881c76e-74b1-54a8-b827-cfc98730b6fa",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eabecbf1-c388-5a80-a519-c0ac7d597c7d",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acbb0b13-d10a-50a7-898b-4f4ac858b23b",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e86d2326-4e16-58ee-bda6-c35271d516f8",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb3e728-a6d7-5e42-ac9e-683d9494fa0a",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e4e8c1b-2dc2-50ac-b584-824d8c54506b",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.10 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.10"
    }
  ]
}