{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:153d1343-ce0c-5b23-9c08-9fe3d26814ff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.39-tuxcare.20",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d4d71fae-474a-5991-8fba-4abf2a29c084",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ab35d6a-71d2-533b-9d47-11c3453b04a8",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738d7c25-9c62-5ff6-937e-98fefc2643de",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b7ac7a-80bd-5eb8-8877-f4b9cc6f05ad",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbb08d08-41c5-5ff0-bade-af55280bf942",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6681793-5b96-5449-b209-f6e0ec27691d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53b50f96-c50d-5172-8645-7c66b14e3027",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e77cab59-63c5-5f21-a44c-48949ed2e145",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.39-tuxcare.20."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bc2b3de-b7b3-5172-8f27-cdcb046cf93b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87ea4c49-96d7-5088-907e-cc3bd2a52ea6",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48bd708e-e16a-5d45-8daf-0452d74c6913",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d768eb0-2227-5626-910b-82b6521162d6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72405895-f405-5b45-a667-e49746652e9f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d295882-12e0-5e53-a2b7-c4b92bfdecf8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b997c14-5bb1-5b5d-88a6-311d4a97c742",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e6df4c5-e9af-571d-9a9c-7ff08c72117b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a603ce5a-4cb4-531c-9376-29dc63c45c1b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53fc321c-8270-5150-8ef3-596edddcf6c2",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543bbb74-27d0-595a-8436-2009275521da",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bb22425-8a85-57a1-8c78-b9228a4e86fe",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f221261e-c088-5636-9063-453ae8688e45",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f75afd26-a0f3-523f-af81-31fa1ce12442",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfdc9e21-7d2e-59d2-8894-8ef4ccd9defe",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51abae0-8fb8-552d-bd7f-cc8370fdc5de",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfe2e7ba-f4ba-5817-9d9d-10e7df1f39c4",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74927986-c1fa-58db-b5a1-067140ce0413",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de10704d-1ee5-5572-a914-88929110eb6f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3941ec6f-44e9-5300-a185-b6c5955f4ff8",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb75c67c-7982-5fa4-9082-bb71cbd8d150",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fa3c7b9-54d5-5e4c-b62c-485e54d91c38",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b408c00b-7518-51df-af3d-95371f25eaf5",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02bafa01-3a62-5a70-b8f9-e59731a4eb0c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef0e717-3fc5-5135-9863-52f2551a5af5",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c6018f6-8439-5108-b574-4b6aff59a688",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1496a90b-e79b-5457-b82e-5d5dc3669ab5",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9be972c0-8961-53a4-ba5e-5ba0aa7100ae",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee6c9b08-6abe-5654-96da-f03da70d7b6b",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bfc7abd-23d4-5435-a5c3-5eee0dca2a01",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca6dd61d-e72c-56d4-8586-66c091cc5ebb",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5a5c0bf-3aa3-50ea-bb4f-0afdc7dfa4ec",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84b64629-9a28-58f9-9cfe-314d76c347c1",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9ca042-1dfe-55c5-8577-c0ea2316e298",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d68c81e-8546-5f0c-a092-e7906385ea2d",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75026436-527c-57fa-907d-b883a967aeaa",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:463aa2b3-eff3-573d-8311-41188f856e7c",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3afaa64-8592-5a28-b4fa-f1c3a08fd7a6",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb03919-ce01-5fdf-acce-c8e1d7bbc3d5",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.39-tuxcare.20 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.39-tuxcare.20"
    }
  ]
}