{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:001624a3-8ff6-5a68-8abe-0ae769b8e2d5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.39-tuxcare.16",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2a6cc1c4-cf04-5dac-89fd-af2a7ca43257",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9e14532-2dc8-5ae1-8c14-508dde68b0df",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.16 of org.springframework:spring-context-support. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b8b507-e049-5902-9677-c876c6c26a4c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9394651-d811-5b54-b05e-6886cb8b28e5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c0776f9-f510-5419-bf23-8ee8277e0da8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d66224-d982-5bb7-89f9-9530e3e6ec36",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c149f8-6f8c-5af1-bfc5-cf35283f9d3a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a4369a2-cb73-5308-80b5-667667670572",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-support 5.3.39-tuxcare.16."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03cb3d9-8a3e-5d1b-a1a7-7150841658ec",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fe74dc0-5782-5c65-9938-28fa83460d76",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b32dd9-f716-5939-9228-3ffad2ecb102",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a7b4f06-5591-564a-8efb-61e5aa80ce4c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690b94aa-e4d7-58a0-b516-02c40ab83a89",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802f28e0-1340-5e36-81fb-3e94d0c7937c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c178da4-f221-58b3-85bf-93a09dd7e478",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adfe05f6-1492-5e76-aa40-5522ab88fcb7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2cf3e28-9312-58b1-846e-a8f145f9aba6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a0777e-612a-5773-8ca4-b611f15b8d9a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6769e3a-aa7f-5771-9d15-6bc49ee24e9f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.16 of org.springframework:spring-context-support. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70886415-b9af-5e27-84a3-22c445139e8b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9daf490-6c33-5130-b63e-e8596a2f9334",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9672265b-0652-5eb7-9cf2-213915060e5c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d28f942f-ae6f-5cee-b8cc-c20f4fe4957a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa577636-4963-5085-8cdc-0a1e1d408c87",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f80473f-e0bb-56a8-8343-2fb60122b4f3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f17ade1c-a8b1-5fb7-8405-25c0a6d98e65",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5e5956-230d-5232-9a57-7ef62e7332f1",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e645df1-8efc-575f-8000-9c71fdc5d6d0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52d8d648-7122-5c3c-a7b4-c2fba2a618c5",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a854608b-ca8c-54aa-9a20-2097316fa8f5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3562781-cbf5-55a2-a06e-a4ecdff37231",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8afbbe9a-e688-5d68-a1da-b75ab30a553c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e45fa0a5-4405-5a98-8a51-27de53a1b532",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.16 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.16"
    }
  ]
}