{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:20a15042-207a-51b7-ae67-a99d85c8f841",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.39-tuxcare.21",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:313b400b-80b0-5ed7-a7c3-4530ea921481",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a47e7e-7d29-5887-96f8-0ea41effeb51",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52dce5b1-29f9-5866-97b7-b5cdffc00c17",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7b46f54-5efa-5c60-9594-c6f686b67db0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec80d7a-9b74-5d34-a6ac-2b813170b4a3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77d1476f-c424-5d8b-a45e-7e889c97b7e7",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b86eff4-ad94-5712-8446-58ea56da1852",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5780199d-b6ed-58b1-b9bf-77288ed8f4c1",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.39-tuxcare.21."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57179988-fcd9-585c-889c-b198a2a3e954",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94c34093-dc31-5ac8-b4f6-b1c35216e573",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7964598e-718c-504b-b64a-dec30176acb7",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7851ee0c-21c5-5c85-b9fc-5bcddb8ad88d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf6bc01-648e-52fc-bfa8-3f5c6252807a",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffe75a9b-9a13-504d-a984-9b45e55279b2",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7fda6d4-a223-5554-b2ea-3c6f1d9291e9",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c797ffc-ede3-5c87-9669-3f4486a735d3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f486869-c008-5d38-b5ac-fc143740af76",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c82b3a0-6ef4-577f-862f-589531ff6144",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82114e15-0d43-5031-9e01-7891ac269b04",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957781d8-88a2-5a01-b487-80bab8829f0d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b04a19f5-6dfc-51fe-ab19-fa24135cd4a4",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f32f734-6b96-5615-9c20-b85e6a48408e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da7382dc-27df-5f61-8f37-4284d03441aa",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4577b7e4-ebf0-58bc-a8c5-5406f9b75aa9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aefad2c-c745-5934-b457-c15cdba51966",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:993b084b-39fa-552d-9bda-ea91004d07bc",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:637db240-2101-5713-9c18-bedde1c5ffc6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faec6146-7c58-5171-986a-af559f152078",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19362143-ff8b-5277-819b-fa2def20450a",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcb5d86e-5afb-51bd-9042-06d51985ece9",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29484a7a-76b7-557a-953a-9a5fdb6e7d39",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2dac777-2620-500e-8951-a21909a4a7e3",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51680b53-4939-5f2b-9d8f-b8a7b5a5f55f",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af7a8b8c-52c7-55e1-8590-9ba390a133ff",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1f8c61b-3dd0-51b7-ba3a-fdf90fe4cd78",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8dd9a10-6796-5c67-9620-b98105d5e2df",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb7fa85d-b1f3-5d81-bd38-c9c146a47faa",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcb6620-5f85-50cd-8d97-f93e535d9168",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfa48d74-6142-5ea2-9208-8a61b785d239",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb0292b4-2e59-54b0-bf34-542db386f633",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e55c45-5e85-594b-9ad1-cc5b0ec18ee0",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ed8978a-1dd0-57fd-a5e9-708341f28c0a",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a38ddb95-32a4-5a2b-b69d-2dbb479d7b0a",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26730128-95c3-5cc7-ad8b-c1946686bd75",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e52050d-e694-5b96-95ce-eb4276c8f0c3",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:954da414-16c6-5e8f-9761-4c4902278f66",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa3b181-fadb-5fc3-9f9b-b36f46d3cde2",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.39-tuxcare.21 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.21"
    }
  ]
}