{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:038298db-8ef2-5e1d-abb6-f3a7b081b83d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context",
      "version": "5.3.37-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7a43d333-9ecd-5372-996f-d7f8540ffacc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c916b5ff-975a-51f8-a830-304eb7f6dc6b",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a205c365-a161-5486-be73-fda48e51ca10",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de922a5-ec30-5b49-8465-4e19a05ae5bd",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29528eda-a15f-54ad-b855-646ac89b0e54",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a0289e9-d47a-51b1-82e3-16f6cce2e45f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:826901b7-a092-59f8-9b8d-57fab60d6d57",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9e548fc-4ff0-5f67-b5c6-26fdff0912c6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfaf2a1f-d4d4-5f23-a5f5-24b2557dde81",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76511f30-048e-55a8-a2dc-2932890f3240",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:656df036-86f2-5c37-b48d-3a0c5cd05080",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6170d93c-5fa8-58c1-806a-fd7d3e46ac63",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba2f5bf2-f1ed-5335-8c81-9f0e012ec7e7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2fcb873-c9c6-5725-b475-6d74e1494b54",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a134986a-248b-5cd6-92ef-151022f6e482",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99a24c2e-14f5-53b4-af93-0c3bdea444bb",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06db76d6-286d-5d9d-ac6d-249e73ee4673",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:863ce1b8-636c-5db9-86c1-bb6bb73f2266",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a73da63a-1ef5-5c9d-b8b4-2440a2ac93ad",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-context. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c203342-68ef-5686-ad86-21ea4af41d9c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c8eac62-ca66-5f7b-8e4e-28696d99fb9f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2270de02-8d8f-587b-9f0c-733b79928afa",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:058f7538-4bbc-55c3-a4e6-a337851c4830",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28853ae0-93d9-58e3-ba54-8c7190b80b70",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c630ab20-9f07-5bea-8f3d-8c9029006189",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d83c5ae7-5bc6-5d9c-be9a-77d445b38f83",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72b3470e-765c-55fb-94d4-49abcb76abf7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f399581-5612-5d5d-81d0-c3c7d57e3800",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.2 of org.springframework:spring-context. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9129ee88-82a6-5ffd-86ee-6c393221afe3",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c87e8ce3-036b-5738-89f2-a5d61571889c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bccafcd5-b732-5a44-878f-c100cc984489",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e1cd0a-6956-5f9d-ad84-7a0f0b729a49",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d985903f-f2ac-5c65-86b0-023043f5db2c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.2 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.2"
    }
  ]
}