{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b007410d-1ce5-5624-926c-843c1535e11a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.39-tuxcare.17",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:54f3c002-e10d-57fe-8f4c-1cf95010f468",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8ed047-c98a-5fe1-afb0-ca93af099da7",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.17 of org.springframework:spring-context-support. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7751736-ea01-5fe0-9af4-d20bb1d03cf9",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efb4713c-1ec0-5e24-99f1-fe2399e3d049",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1103bf-4749-5256-964b-5d51780c95d1",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ddfac9f-3d0d-5970-bef9-e252dab5d371",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59d95daf-ddaa-5a2d-a458-30f2bc2d7ba1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3d111ee-ad75-57c8-9810-14329ae45b6e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-support 5.3.39-tuxcare.17."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb2ae712-0c16-5cb5-a4c9-446656417e21",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d903c16d-243e-5e5d-b5b2-6c34e6605cbb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eac37ae-f6c1-5436-9e6a-050da9fe93ee",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a4ceb7-c7f6-5985-8cd5-d1d5305e003d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c9a40c1-3112-5b4e-842e-c31a6b5ebd94",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb77065e-177b-58f6-b38c-d5536f4cdb56",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5326af7a-44b4-5638-b081-0961560699dd",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8816d38-9692-50d5-9339-e1f9f942cfd9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d0ad5ab-99c2-5e80-90a5-1b01035f9526",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd8b9762-eccc-5ab8-a800-444917c7eef3",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee69b75-198f-52bc-8f78-bfc553ec34b0",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.17 of org.springframework:spring-context-support. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73dae924-0a25-567f-adc0-1057fccc6b1f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e7e2ca-0838-5c10-92a7-fac5206b0801",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:314b97e9-59f6-577c-955e-b9b04acc7235",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43d87c5a-08f4-58ec-aec7-b79f8f7e99d4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18da6eb3-5a48-5235-b00f-b39ae4fe4311",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d395425e-f3d2-5635-9b62-49a6b0d5cea2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:074f8cc1-a081-5cf3-ab00-0c1ae3341e4e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3a37a7c-5914-584e-a21c-30af3cc3224b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6b79668-52c1-5303-b1e6-a269bb9acfe1",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c88d6f8-3ad1-57a6-8335-b288e27c6b1c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e8902a-ac22-55c3-8d75-d0689c9f3b82",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a22e64-6cc9-5e0f-b0f2-94090dd7630d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbdb3888-a531-5a4c-8e7c-4392206fab84",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a277e369-c8d6-51b6-9c49-11e06db16a58",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.17"
    }
  ]
}