{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4380b307-d055-53eb-868f-21dd6a7e37fe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.7-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c120f6d0-ca25-564a-9988-bf98581075f7",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40027445-87c1-5eba-ae31-d896a74827be",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba55e4a-2ab9-5a2b-b601-2b0ecc774798",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e41e3cec-7641-501b-bdd0-1772a84599a3",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7267d9f9-ea97-5b99-bf7a-5ebc70f0a2d3",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eae53b7-006d-5c27-9318-6d67e8873ccc",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6e54691-1fcb-58d1-9ada-e658d2a18303",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:414a2274-ddf5-50c3-9f0d-bd6c9bb32b7e",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4003a0b6-fc04-5ea6-83fc-d13273331f03",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33df0b7e-28ff-5025-ab90-5614951dad2d",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd99ef87-ee06-57fe-910f-8f42a8e7c774",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0863486-1220-581b-992c-0cb37b44687a",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f5faff5-d03c-58fa-a4f3-4fdcbc0f3a51",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786bbc0e-ec62-545e-b199-9367f3317bec",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a703a78-8b23-5112-91c7-3396f585bb2d",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e3ce705-537f-5c4d-b90f-1a312de7e04b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62df1a3e-a3e7-55b5-81d0-cc430697c468",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12743857-e2d3-5d79-94f4-7dd6957b31a0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d2ab098-bfc4-5c70-a187-2a38b3d8ed45",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d6da195-f1fc-5ec8-a456-a54fe021fa33",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11871fc5-43bf-5879-b641-8b415d2eb2ef",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8467ccc-1209-5502-af93-e53a1b62506e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.7-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7f4b83-9e3d-51ff-bf24-262714c99c73",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ec9170c-7a2b-53f9-a5da-5ab058d15476",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a420d86-436a-5959-8200-55bd069f6885",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c712ce17-5c83-5a57-b9fc-ab39c0183737",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94aac7bf-140b-5c3d-be12-35a893616451",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.7-tuxcare.1 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.7-tuxcare.1"
    }
  ]
}