{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6a6c3cf9-8145-56e1-b9c7-1e5583f6e099",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "6.2.19-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:495f8d2b-6e30-5ded-b69f-1e0bfd2cce76",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. already_fixed \u2014 CVE-2026-22740 has already been fixed in Spring Framework version 6.2.19. Both upstream patches (commits b338fdd99d and 474d520182) that add doOnDiscard handlers to prevent temp file leaks during multipart request cancellation are present in the target codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:482beddc-c0f2-5284-9a6f-69b4cb38c366",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22741 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. already_fixed \u2014 Target repository version 6.2.19 already contains the upstream fix (commit 46867fad81) that prevents cache collisions in CachingResourceResolver by including resource locations in cache key generation."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8de335ef-aa3a-5821-99be-fe9e592996c8",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22745 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. already_fixed \u2014 CVE-2026-22745 has already been fixed in Spring Framework 6.2.19. The fix (commit 684b1e8a4b) adds a file.exists() check before file.canRead() in FileSystemResource.isReadable() to prevent expensive file system operations on non-existent files on Windows, which was causing DoS attacks."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d58e0e-cc3e-5d6b-9070-bb2bd323fd80",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41838 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6586ced-5573-5e55-b4f4-f8f9dda48ef6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41839 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5734755-0ba4-5bff-b2b2-adfde9714067",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2176004c-56d3-5346-9d47-be985d06f68c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41841 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework 6.2.19 is not affected by CVE-2026-41841 (cache collision vulnerability in CachingResourceResolver). The fix was included in the upstream Spring Framework 6.2.19 release, authored by Brian Clozel from the Spring team. Both CachingResourceResolver classes (spring-webmvc and spring-webflux) correctly implement the fix by including the resource locations list in cache key generati..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b61d1ca-7a51-5b01-b046-8cf8c6648037",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41842 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55ed46d8-371a-571a-bcde-d979a3ad2663",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41843 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d6ca0f-3798-50b2-8bfc-9777488d38ed",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41844 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:853daaaa-716f-5396-9f9a-f0e035e3fdc0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41845 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54ae49e7-f740-5a5a-ac46-d08f4792ff6f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41846 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e712d93-c316-5d5b-a352-fe0be04b0b27",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41848 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. not_affected \u2014 CVE-2026-41848 (ReDoS in AntPathMatcher) is NOT present in Spring Framework 6.2.19. The upstream vendor fix (commit b294371a46 by Sam Brannen) is already included in the upstream 6.2.19 release that TuxCare onboarded. The fix introduces a MaxAttemptsCharSequence wrapper that limits regex matcher character access to 1,000,000 attempts, preventing unbounded CPU consumption from malicious patterns."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:807ed561-38d2-5714-a61a-499849c48f1d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41850 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08adb4a2-9eeb-56c9-9bda-b443cd69273c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41851 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f0ebaa-21ab-57c2-9834-e686ecf42176",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41852 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f464f8e-0ab1-5b49-8cb3-f68d8014f72e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. The affected range ends at 6.2.18; Spring Framework 6.2.19 is not affected."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca684f60-8acf-5ee8-8695-759874007580",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc. 6.2.19 is not vulnerable, as it is\u00a0outside affected range (>= 6.2.0, <= 6.2.18)"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68b5b658-2f2e-51f4-a1e8-4429f325c899",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8315b6e7-2d03-5c5c-b807-821ada85d1f0",
      "id": "CVE-2026-47883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47883 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bc0cbd0-d9c6-5d66-9068-fb633b9d9508",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:845ef9c4-e67f-5643-a443-bd5d5f487b8e",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cafe1d4d-73e7-5419-8da9-0330f679f2ad",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:092e2609-6303-50c9-90c3-16f014425c81",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7656612a-898b-507e-b720-3f98440d482c",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f73fcde-c5ff-5010-86a3-56111a63fefd",
      "id": "CVE-2026-47889",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47889 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f13b438a-4c94-5970-b694-088314bed727",
      "id": "CVE-2026-47890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47890 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8c652c-711a-55f7-b283-f333bb4b40f8",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1310f47a-b896-5e91-b79f-6a2d907fa8bc",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715478c0-23dc-5bc9-b080-caf025bd4a2a",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1b410b-b5fc-563f-99d0-c4d573da82f0",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c37ce841-92f1-5e24-85c4-959378e43d1d",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30f47be9-bfde-5abb-a7e6-c234c51363ce",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfedc795-41e0-5ecc-a7c1-d5add6bc5568",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d8d5cc9-bfec-5c6b-9162-40c82bf83e60",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c717bf98-d946-55e0-81ce-723a12a4f6f9",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.2.19-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.2.19-tuxcare.1"
    }
  ]
}