{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bfb07ac9-bca2-519a-9546-b27d24e9b09b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring",
      "version": "5.3.37-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ec3869b4-a74e-51e6-b6de-82d402db6df3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370e41df-c292-5df9-8e44-5f8d0be79f12",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71aa1046-389c-5c82-81ef-a2431863d80b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49156cbb-80f5-5c57-a061-edbbcdc0adb1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abe21434-fcc6-507d-922c-896bb2deef9f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:929c28f2-3faf-55b9-86e8-323acf34b4cc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae57dc5c-417f-5631-92d4-089d5ec5ef0e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e9dd703-84a1-5a85-b4d1-b3da6eff5124",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ed0242-b781-5f59-a036-1ce7916666c0",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d2c5e12-8857-5b32-9dbe-997a5feb0ddb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:536f6c14-bc1f-5f64-ac0c-a83338e611b5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd67e8ae-7a08-598b-9f63-c409a5812d82",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98a5f761-2087-5a1f-a1e1-c05b721deeef",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3708348f-2b98-5851-a764-1fbf978bcb84",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771e7d16-a985-5460-b09c-ce05e02e77ef",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635d1f69-b9ea-50c6-af98-8f0567c4e1ad",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb0862a-24a1-5a3c-930d-5fd07e95013f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf4f16be-f0d3-5b36-a890-f0ffc3da64b7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:939cd7c2-5f47-553e-9966-0317a5abf10e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50e6f0df-79bc-58e8-bc41-1cd02ea30d90",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2eeaeb-7820-5aae-a59d-a7423d1d177c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdcde337-b6ee-5dc3-a996-6ffcae399c8a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34caf8b8-81af-5669-9aab-458b21bcced6",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea00616-a4d5-5e3d-a51f-a6b8218c4369",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:211b688b-6aad-5cdd-aed5-f2baf0ad10aa",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aacd453f-b3ba-511e-b9e1-d75fbe41bfe1",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6a60813-d0c5-54b5-af1f-8db7dc849dec",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8755e523-e082-57b3-a5a3-c36d0bcf3db9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab65ff6-2604-5036-bb7e-3c50b6aba42b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f07ba7c1-67c4-5952-8b37-92e07d2e9df1",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38b6bb00-af78-5684-ae8e-8bd30f292754",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d95579a3-335b-5fa8-b54f-c4dc49306a4d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44ed2dc2-d8c1-503c-abb5-7e70227fb08d",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6373227f-68e3-5e7c-ac43-8843431a6497",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c752dd8-e915-5971-b362-05e5ea693779",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2280af6b-3365-53e1-ba53-d106ac4db4e1",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e64d4bf-5a4c-5a19-b706-11977f0cd588",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7db375e-ed03-54b7-819e-2d2bcebd3830",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3526a3b8-a478-5c7a-80f3-2d5eb577e1b4",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:322320d8-6f78-5c35-8d57-8414a3acb68f",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b64aa916-f238-50c9-9b45-14d5d674e9cd",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:943140fe-3881-56a7-9a0f-0a5791f108b3",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e03741-c96b-53da-a99e-5f788ee8334c",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd48e85-eb68-5fc7-a03b-9cd0883da8c9",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:667a0826-9fd5-575a-9c9e-fcb85af2bdc7",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b15f2c8-fd30-5825-8973-9538092955d2",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:702181e5-ea24-5bb7-8e56-edf7bde7e00e",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.10 of org.springframework:spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.37-tuxcare.10"
    }
  ]
}