{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:02c678e9-1cdc-5b80-b0b0-2ea5d1955b2c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1",
      "version": "5.3.33-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4a0f0e2-b904-5eb4-822b-e1c0581b57f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0a82156-ee4d-56ba-a34f-fdf35bd0dcd3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78223fb3-652d-5347-b1e2-ed2bac19d27a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b40e856-cb6f-5728-8eed-b1387e97b8db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5325660b-9fea-55d2-8cb3-d35a10175ce2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8796065-7cda-5c5b-879f-e395b93b89cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b5cb0c30-cea5-5c81-ae4f-668c7fd0e780",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb009e6a-ab8b-5c7d-bbf8-e68e987e501e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6af9f5e4-62b4-51ec-8de7-2327c1e76913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8d10fe3-f6e4-5c4c-b7c1-da81547744b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b1aac7a-a26c-5c91-b798-fc05a5913cc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7432ab0d-9dc6-50e9-9b26-acaa2e54e54f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d87bcb63-3125-59f0-a606-e3a25ed222ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30bb361e-dc42-5dbf-b1ed-86fd0164d95d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:31628c80-a465-5058-9d88-3e8330eb885d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0e2a76c-080b-5c47-b4c1-6b4c36cd0031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c82ccfc-f7fb-57d1-8f34-c26f9ba740c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c69309c-f8e0-5d84-bd57-1f1277fcd37a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:235dd324-cdaa-5386-9bd1-3738c79d71b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30b44560-0b97-5274-be21-99e6921d867f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:90a9665a-e17e-5fad-9734-6d522696f6bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:995fa9be-50e1-5633-9a04-bc5439eb6fd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9c7ee5c-3e04-51a9-95f9-a507f254a9ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2896da2-7619-55f5-89f0-65673b0f3e30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70b0eb80-cf87-5289-a024-22743225af9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:365c2fee-0bb9-580d-a33d-241e02dcf3a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:306cc026-f65b-5b60-b117-c6a8e77348ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bfaa0de8-52ff-51e3-8a7f-c6de7a2cead1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:108f22c8-afb1-5d3d-90df-935642cc65e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fbe5f240-08bb-5586-ab9b-91c50e034e86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8a6f11c1-fc83-5bf2-a69d-079288d42bfa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4ba6cf1-dc82-53ca-9903-c90b51a28353",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e438241-b045-59ff-ac22-96e466ddb12b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a36ccc00-f9a5-5ff6-9973-febe914bced0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d94fd542-5217-592c-aa86-efd48b6fb668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ac50764-3c1f-57b4-b350-34d565e7622e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:256fdb27-5dae-57e9-bb7e-215847753f85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c185622-3bc8-5d1e-a406-d72cda80e87b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e1ea1c2-bac0-5e01-87bf-627921570c63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c2fc03b-79d0-5690-92e1-9fac954f7ffc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f5afcd90-c77e-546b-b583-48120d5b822b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:427e256a-a652-5c58-a2f6-19d6792cb4a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0472636-d3bf-57e1-9214-efc112293946",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b980eabd-98e5-5eff-affa-08fbc1f81ca4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5f7b4119-18b4-57df-bb10-bb2636d35636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d56016bc-2fd8-577d-81bd-5763f74c70b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aea5a268-3720-5dc5-831f-43d92e310188",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:92ccef17-9c1f-5899-91db-9a1f80fb14a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.33-tuxcare.1"
    }
  ]
}