{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f6d8c273-2194-52b7-b61b-c42aea47c03f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "5.1.20.RELEASE-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b8360bdb-0e57-5cb5-8838-b52c0cd67d12",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9f80f3e-45b6-5dad-80db-89ec6fc6c752",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a98928b-7c7d-5c43-bb8c-6851fa082b09",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53d54d9c-de8d-5a21-842a-1dc21887f33f",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e7502a7-b958-5852-8b10-5ae3a2577647",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03aa6d87-3d2b-5523-92d9-282752b32db5",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf8be5d-4c0f-5f14-96d9-8be17e47de7c",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a7f0a2-7187-518e-bd06-4de3b45df42b",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a490239-d4c1-5dc8-b5fd-aab1496604a1",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d6f0cb-c443-5c98-8631-8c8c980c176b",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83948413-c643-5f45-bb13-0c0f7b17d80b",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b0ac7ec-504b-5a53-b6ef-26b2f90007ca",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84699d46-a81d-50b6-bf0d-150c52ac410d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cf3d59e-0da6-5bc7-a49a-3e925e643a3f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1de3372-eabf-5b91-81a6-b047c8b7a018",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92b69bc9-a154-5a11-b7b9-ca042dfa2911",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-context-indexer 5.1.20.RELEASE-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:537bbee8-beb1-5c43-baf2-db20738e4208",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd86082-480d-5341-a64b-310d071a6c4f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16f6f212-5d6b-54f8-9e0f-7c0f9740b4cf",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89ac8aef-c850-5462-81b8-a20f8b0c617c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15cc31e3-2d03-5200-97b1-a274c685c0e9",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e1abc9-7716-51f5-8547-f980afd6b525",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:597e3bc8-0cba-5cdd-895d-bd4cb73caa72",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1223f138-df0c-5a40-81f1-16e8e9516acf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a0bb3dd-04ce-56b3-8bc9-7e3953bdef39",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bfebe73-cf17-503e-90d1-66be7f8f9991",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce0995e8-53f8-5313-a38f-40f6cac938dd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75ff58a-1432-5cb5-9b05-bd050ec17927",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9081981c-4bd7-52a0-8678-923f6e39244d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a414d9a0-639b-5080-9530-fe211fb7c17c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed65b367-5336-5d76-aebc-7b2a99a5b887",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d029a921-469a-5fc0-8114-2b15f2af6cc5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc13051a-acd7-5687-97cc-206c33690d13",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:369ba760-7e90-5fba-92ca-6eb1d9fd03cb",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e27d17a-4ecc-5866-9bc7-e21aa5574a99",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5be4109-d781-5c73-87e8-f37decd8a3cc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b24f2197-8aaf-5c34-bde2-85756bbc0663",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7891eb91-d772-57fe-90d0-e703a050c3ac",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8f5bb9-36d4-5dcf-9137-3c2eb21153ca",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9925a75e-9872-570a-ae15-898b9612f21a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d97290b5-8b0d-507f-84a7-e349a97d7bda",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c22c4ce-220b-5e64-bb34-70e3f7c12934",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@5.1.20.RELEASE-tuxcare.3"
    }
  ]
}