{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e3741bf-1bca-5802-be38-2e51457dd27d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.37-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:27941f05-4048-54f3-a21e-bf7c6d043f31",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:726486bd-e170-509b-aa7c-b74e48b9a391",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ac2d58b-14bb-56c2-a169-53fbf51b10a8",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdfa7b0f-d3b1-555c-beee-a7d1eef0852c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82d83b19-bbcd-505a-b40b-4e1b133cd12c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8eb159-1d6e-5d62-96d4-45377056ceb5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6576cef-5d56-5003-be3b-5306a38ee1e9",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:834e5fa0-ebec-5232-80ad-84f1a8340503",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60332bdc-aa95-5aed-8728-e1f2c9900ca7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e351cedb-cb79-5fdf-aec2-dce56fa9d466",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe8f3ae3-d803-5bdd-bf4a-df8e02f6cacb",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a3132be-8de4-56a5-a7a1-15a32d6bb5a1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce0b781-36bd-5b96-a66f-05303c70060e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aa420df-fb3e-5dc6-b913-4f3d44fd281e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76ab80bd-4c37-5965-90a1-18f6d84d1cfa",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ea10e9-f520-5dae-85a4-1120f29aec8b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf8eb57b-51a1-5f2d-ae1d-08d12a97b3e4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53c53626-02ea-5d42-8e3d-cbae8099ce63",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1626e61-6a8a-5c80-a4ec-e10b38239ec8",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-context-support. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f38f9b01-e390-5143-9fa5-c9af0ac33963",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:844e009c-8efe-5b51-85ff-ae1f73296bed",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ccf85c-b842-554c-b19e-63181588dd82",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1881071e-8b7e-589a-98f6-eecb9fd9e9a4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bd78141-5517-5c75-a346-c1f3a9fd54fa",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acde8a4c-efd3-59c4-a2ce-c2e278a06cb7",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e322a0af-76a0-561e-af71-9094c4836424",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da95609-6418-5386-90c2-c9ae8b80b96e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d3fed2d-81e6-515c-9a30-c626ee30947c",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-context-support. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7810b8b3-baf3-5fb4-8092-069915e23caf",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd0950f1-7cb2-596d-b061-41aade33fdb7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d40a03-118d-5ff3-a13e-11a4dcb61537",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9993e69-6e7a-5fe4-aa19-56bf6d9e22b9",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:259d1f12-34bd-5af9-80e6-f3d9b5f3d934",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.1 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.1"
    }
  ]
}