{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3185f714-2be4-536a-8520-c728df5c9b18",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.37-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c4c4089e-941a-5d7b-ab19-d617649149a2",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c9cf50e-a6a9-5f02-8f38-e82186c1483d",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c434741c-6549-5fc0-ae6f-524ef700597b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa84d2e2-01d4-50fb-a129-5d56343b8689",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d03441-2421-5ebf-8f2e-c66d5b5e3b19",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67caa79-a483-5dbe-a4a7-b6189bbd63be",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8538eb-bdf5-5934-9083-28365f0838ce",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdb89508-eab9-5dc3-af99-9cceff9b3a45",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6b55124-28a4-5521-a088-bb711da1c499",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52ff9373-3d6b-5548-aa0f-657ced56a6e4",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cb8eddc-1200-580e-8a2b-99633dbc5763",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ea070c-e408-5018-9ec8-7f824c604627",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b199e8-5c40-5887-95cb-f2c5880c6bbf",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c14eb03-8a76-5afe-9c7e-de02b9a512ac",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55beb349-74de-5b75-ba27-16a9791f829c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17994093-e95b-5870-8583-a38cd1ea351e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd8c7eea-9a09-51a8-85d7-b1734ee4076e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cafe0984-7654-58d7-9280-4204a2dafd38",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af137c05-444a-5e0d-8f48-f38f46beba6b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.8 of org.springframework:spring-context-support. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff311fa0-82db-54bd-8a69-e4723fef1bca",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ead424e2-9471-5be5-9ec2-728472c9fcca",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30517928-ba3f-5dc2-98e8-0278194e495f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e68ec8d4-9f17-5de6-bd6b-c5ce53232e42",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fed92bd-7a6b-58f5-97ae-8c437d49e0c4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c4bee2-0576-5f51-a97d-0807e9dbe55e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c103e43a-33ec-5315-87a7-8e0d06908b0d",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bb9e5d4-6db8-5c53-a0c6-5c0d7b45271d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4a8ff2a-8a21-5f48-9eae-31c0f4d56534",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.8 of org.springframework:spring-context-support. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ba07e5b-7e5e-539a-8bbf-13c96c40aa0d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f191b4-50b8-57e4-a64e-d54f3b36ceaf",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90be7108-0193-5c1e-9ed7-8ad7b0e291e7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97ff8f16-a172-5d8c-8748-e4145e45b2ca",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcac1f08-eb86-52a6-b4be-a6ed26b6972a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.8"
    }
  ]
}