{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:799a42f4-4c1c-560b-ac79-2947f4e2b6a1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context",
      "version": "5.2.13.RELEASE-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:72db0e89-7a9f-525c-8705-ab7f411c5be9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16354957-39ef-5ef4-a65d-aa9de983ecce",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:663e39c5-39b1-5483-bfa8-42dc867c6aec",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff04a12a-3e09-585b-a231-d66b595bfa19",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b61556b-61d7-5c1f-99c9-ca0bc54ab8b7",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fb12dc7-81e7-5a48-9dcd-b5717a743f67",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96de6e34-04e1-5e23-9123-89209ad57541",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45f62122-1602-559d-8268-364b4623548c",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a3597fb-2c34-5860-bdd0-2bed4f172799",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7efcd06-9a05-50bf-801f-440b0250086c",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cc94fd0-68a5-539e-bfa6-864a5fed5db9",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed9b49d-0dcd-5428-bc4d-bbd2d0d9c975",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d9ee8ca-189c-56b9-a708-e32918dbf413",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2a629be-11a5-53ce-81a4-b97d925e0a85",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea980456-5749-5edf-ab54-277d0f63ce74",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be9096c-a739-58c5-8c53-12f222c7dcaa",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a1e6221-8f38-597d-a6ca-a846ded303a5",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da608c4d-faef-5dd9-a0b8-b9904758b26a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15b7b160-9407-5d59-a3d3-96b10f4196aa",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3a31b4d-de07-5a74-bef0-b412bcafda7b",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3c06b61-2adb-5980-a23e-5242744fd851",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41234 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bda7ab64-d82a-583c-bb22-101968723732",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c7ac8b-32f8-5926-bd63-41297bc2ca88",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95de721-bfde-5173-8558-23385fd7c8a0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d7e5824-268b-58f3-bad5-d98f2aab8dd0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0833b5b-5f83-5cc1-9427-e027acfe2d99",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65ad262e-462e-50c2-bbe8-55b27c7daeeb",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308831a6-32ab-5ca8-b3fa-0e13ad974f6b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:701f214d-cfe6-5e56-a7c0-328657e2bd7c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context. not_affected \u2014 Version 5.2.13.RELEASE uses a fundamentally different multipart parsing architecture (Synchronoss NIO library) that does not contain the vulnerable components targeted by CVE-2026-41840. The CVE explicitly lists affected versions starting at 5.3.0+, and the patches fix issues in PartGenerator and MultipartParser classes that do not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35baa6b2-d797-575f-bf37-fc2196dd1ef6",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:078f83e4-8eeb-5d47-b457-5344d39bb807",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e8c4b90-a449-5709-92c0-2db39b79a960",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:291b4ef2-fa80-5493-8bc6-3ea03a1eddf3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21757591-4926-5526-b3c7-920c774da782",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95fe7fdd-dc1a-586a-852b-7b5f2ac6d38b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fc8506c-54b0-5579-9106-36b384aae4c3",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6fbf31d-9a1e-599d-8280-aa5b0c8c4912",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70fe7008-0953-5ead-ba86-a1e9b90e5fc3",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7499f5e-0f69-5bca-873d-ccf5e13d31c4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e74375-0d23-5c75-b318-f4d4b1bbc01f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a355d99-d452-5358-9c9d-22767a675ac6",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6de5db6a-2576-5b1c-b52e-73dc9c1464c8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context. not_affected \u2014 Spring Framework version 5.2.13.RELEASE-tuxcare.4 is NOT affected by CVE-2026-41853. This version predates the affected version range (5.3.0+), and analysis indicates the vulnerability was likely introduced in changes made in version 5.3.0 or later."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:082a8fea-1e53-5414-925c-26ba0a112cf5",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.13.RELEASE-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context@5.2.13.RELEASE-tuxcare.5"
    }
  ]
}