{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:80f325a2-e46e-5a93-ad4a-a29e7d7f7edd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context",
      "version": "5.1.20.RELEASE-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4ffd4c42-6f38-571f-b8f9-34bc568432ef",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df63fa4d-71a8-5a09-909a-8be3a6658b9a",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:043accce-5258-5e9a-96fd-e7e0dbacf01a",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a374ebb0-38b8-5465-9101-b870998a9a36",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dac49f2-d65a-58d4-aa64-b904a8dc48fc",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e273c4d-7d99-5ddb-bb90-f90f0c733555",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8d41dd-5e0a-5de5-b819-9574fa71dc93",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ef8358-1993-543b-a2ad-d794a1850c52",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:172f66e6-a110-51f6-ac6f-1b719a711f64",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6c27c8-54e7-5be6-87c7-e8ddbf94566a",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a0245a-c1b5-5b6b-8435-f5ada32cb621",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e50e71f-e5e4-54fc-8f0b-229275db323e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0876092f-ecf7-5a0f-9383-15e8c2383ac4",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103da662-7c33-52a2-9817-4ae61f9aeaeb",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a57c6648-c0a4-5808-9c8e-e34a846e982e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af0d0600-e577-5b0a-9bb7-bab8b272d3b0",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-context 5.1.20.RELEASE-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8e52ee-681c-5754-bb15-7b9b2fdb0442",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39565cf8-578f-54b4-b8bb-0a0c535a774a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf5afa12-a941-5591-b0e3-19dfab5b0cdd",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddf8b197-b02b-5ed3-a200-1e56b8d4878b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c8e71d-95a9-5803-a424-46300ec09e6e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c228a7a-7e59-55f1-886a-6dd4351ba898",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64cb5e6c-ff43-5951-96f8-afd6efb0c671",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:135e0bf1-d081-5464-bf45-ff7b4c676f7c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:463c2601-820f-5618-b60e-6733615ba240",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3def1656-1786-5b7b-92f9-f05c5d7f5a2f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd0d3fa4-83cc-55e7-af06-743fa25a5ce8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:616404e1-c475-5e68-ab5e-f914f4e0111a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:801c9603-e779-5847-b605-01eb648ab49f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5c55cd3-dd65-5ee8-9e83-82911a765b7b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f5f71ef-a815-56e4-8ee4-ee9d417d4bb6",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5da93add-0042-5a3e-a64a-00c165c91b04",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03fc21a8-6f35-5314-a5de-559832d4ed5e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01f697d7-231e-5abc-be98-3bc0f697e33b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21187ecd-65d4-5243-9114-69a786e6bee5",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b1cc87e-95ac-5f2b-bcee-1bbde113937a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce395e7e-fbb8-52ff-92e1-799a02884769",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b935db2e-440c-5247-ad75-17d06f80822e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78896dbb-eb9f-5ba3-9572-a7f85d4c8e93",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72264a1f-4c77-5628-9cb6-89d02628dd5a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e1bd744-9675-56a0-a7ed-85088f3ef24b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a2305b-1fca-58e7-b24e-dbfe9e461617",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.3 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context@5.1.20.RELEASE-tuxcare.3"
    }
  ]
}