{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4c2367e3-00d7-54fe-9d5f-44bd98a7cfc6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.30-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7f27dae3-586a-5df2-84d0-c91794709830",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fddeaed6-217e-5dc2-8b2c-85bf0b01b2c5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7df3e01-8b92-5d1e-bde9-6de34c5308af",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1736b8c3-5f22-56a5-938e-a6889bab8b36",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe86d85c-628b-50d7-b5d9-37958b2baf88",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:472b0480-e6e7-5a1c-8982-a06adc8af557",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc157705-6c79-5c28-b085-0779aa4070cc",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2958e230-4cd4-5a4e-8d5d-6fa27733de5b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1f4683-38b8-5e4b-932a-69b775c45e63",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bac00621-4e7d-51ed-8381-d162c5d8f141",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:523f8b31-1468-57b7-b807-2cfbb63cf47f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad653d6c-429f-569f-a02e-6203b3c7b29c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b18c700a-66e9-55aa-b642-2a7357afe7a9",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a31b2449-3bfd-54a4-a321-147b5ebef593",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:882b4817-b96f-5aec-a4ee-da3cdffad005",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed42b18e-a438-5fa1-af91-d8d4f4dbd7c9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b63b5b2d-ea98-53d0-8681-708076846b9a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ee468cc-3497-5f09-9a88-010fea9bcf4c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4d6673-b42c-552a-9bda-95ca9d8c8a4d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e586473-3bcc-5756-98bf-c4b99ed9ae47",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aebe815-7f5d-55a2-a071-cf2fa0fbb22c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a2f3256-4ea9-5a7d-a144-5682204aabb3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.1 of org.springframework:spring-context-support. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6853dfda-b013-5e89-86ab-5091b5a1d0cb",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2bf7192-c544-5a17-b2d6-ebe6c6b86626",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4529c8a2-7ad7-5484-ac11-0e12935fba9c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d1f0a79-99b0-5125-ae06-6b6d8d1bf320",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9165e93-3a2e-5d17-bf13-42d5d2458946",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8676886-da85-5f93-8bd9-484c6531eb11",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25405f32-b755-5eb8-8698-2a2389a89ee6",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc054eaf-ddb8-5470-8187-722bd7d49ecb",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdffaf4-3add-5c57-a11d-373dacfa0707",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b08d653-7114-59ab-b17f-4df725bdcf24",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54dfabd0-7c28-5527-915e-645f27a13d3a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eaaecdb-edaa-5727-b08b-84885b6ac207",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb810404-9ce1-543c-adaf-869698c6f725",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12bb44e0-77d0-5db2-9043-30de286f7a9a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.1"
    }
  ]
}