{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:74c66790-e3b7-5be7-9e59-5256d4a98a5a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.39-tuxcare.22",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c7b855e8-d1bd-5f0c-9425-452377d7faa3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75bee549-c58b-55e4-9b55-66104bfd4fa5",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:967d7441-3c58-5c0c-b6f6-105bde73a7b8",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baceecc1-9dfd-5456-9eba-d31507741f14",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9647ca3e-2831-587f-a599-3d69d4ab41d8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed376826-9d2b-5c48-a934-0726a4b4620c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5987a311-80a4-52d6-acec-1115758b2283",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:800c026b-af9a-5c97-bfcc-bfcf7919a747",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.39-tuxcare.22."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5f77b3e-cad3-59ae-a066-5c7becc49094",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:273f5774-66e2-54f7-ac40-89550cee1b06",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d5ef6b-7da9-561d-bce1-27c778f8d766",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd647962-11cd-53f5-ba82-23cc050e8abe",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e7a4851-d9e3-52ee-b0af-9748f95cb251",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc0f6756-2435-561b-8e32-53add153119d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ee7437a-0a34-503a-a3c0-e95bf67b0d23",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b26767e9-ca14-5a21-b7b1-e1318162bc41",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57135b8f-149e-5d83-a100-ba6fec755ea0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfba4cad-48c9-5ef6-b94c-e0d899514c96",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dfe1f00-e083-53ab-88f9-78753d9ebeba",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7684f2e6-4fd6-56d3-bfe3-f9c4f62900c9",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2010b2e5-3ca7-52aa-b270-8841240f8124",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6538a17b-5326-56ff-9063-0b24c7ae750e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb6ded36-b15f-56d4-bbb7-e9df771837b5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4ff813-c207-5021-9ade-df7878127b10",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90fadbab-dbfd-5213-b370-c59a9e177d03",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9918f483-8988-5db3-98cb-49dee324a3a9",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd6262a7-9e9c-5df8-828a-fa3e9c35c18d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd94f33-c6ef-5b82-b23e-e4e1708f53f7",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b713baf1-9451-5eb1-8a0b-81bdb3af1b5f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff51049-f997-59a4-be5e-83204aab99b2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f85c624c-cc9e-5007-8bfc-1e1078e0c7ad",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bacb44aa-cf91-54ee-82f7-fa68c16f132d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02bb532b-d214-54f4-9c43-ca58394c87ea",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3c2d94-d63e-5061-9b2b-57ee84da32ad",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b7f102e-d93c-5eac-962a-9e8ffd986580",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9bcac9-5d16-5bd3-9a29-fcc5b4581123",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9bf440e-212f-5daf-9b5b-5bc472d0d7c9",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b29aaf0a-1691-5868-b32a-e97ed824c527",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf97f54-14fd-5345-baed-59b663a3b1f2",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4e80469-8e84-5e3e-9e9f-9d2ce65139f8",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:069d3d99-8a41-5754-960e-39c3c1134a27",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:883d9096-550f-5537-bc95-a5feaa7353a6",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe2226f-506c-563e-ad77-7d0e235ee02b",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6d85342-9a9c-5fd2-b428-e53861bb20a7",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:476f60ed-78df-5559-afa5-6759137059bf",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e55a83bb-9166-5cf6-84f1-08de4da0e045",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62865b13-35bd-59b4-8d6c-a69b3aab237b",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.39-tuxcare.22 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.39-tuxcare.22"
    }
  ]
}