{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c31060f3-6bec-533d-84e3-54b6833c6e7f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.24-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1425bad0-5a69-545f-950e-3f23553015ff",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b5bdbb-a36d-50f8-8ecb-e8edc61a0cc4",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9d6821f-3003-5a2b-b4df-39f8e31749fd",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bc44811-425b-55b0-9f20-055bba354566",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3a31387-4816-56ab-99ae-6301f6a491da",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81d9546-eab8-5c3e-8078-88dd49234cfb",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d94565-da21-584e-87d5-0b90fbbc84c1",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e561361c-86ef-51df-ad91-77024620bd04",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e34427c-da09-5ca7-89e7-59027ee04e25",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cec2813f-f1b5-55d5-84ea-3d2cdccc18ea",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bf65d69-664a-5ef0-bf31-6fe5235c006e",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b19583-26f7-5cf9-bcb2-aaa1529f601f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd4a264f-c068-5781-8436-b190e7197c74",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6edb5bb-4636-5845-8bf1-da32ddf4096e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2898cd07-c69b-51fa-aeb5-6a0c5865f50c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd8627c0-273d-5433-830b-f2bfe23cffed",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7749cb0b-4f92-5950-b9ac-05d50010d68c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8a03409-d0f3-5acb-adc0-e7605ce8211a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92a24a66-e542-5147-94d0-13fe054e1e1d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.1 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.24-tuxcare.1"
    }
  ]
}