{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:12e60481-245c-5d4b-bfc1-d02c3925d00b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-security-cas",
      "purl": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2",
      "type": "library",
      "group": "org.springframework.security",
      "bom-ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2",
      "version": "6.2.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-22228",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d29e5fe-f3dc-5100-89ca-34db23e90393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22228 is fixed in version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    },
    {
      "id": "CVE-2025-22234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:16e3a527-f007-5e78-83ba-f37be706ae13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22234 affects version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    },
    {
      "id": "CVE-2026-22732",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f9da3bf7-2627-5226-8dc3-580d96cd605c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22732 is fixed in version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    },
    {
      "id": "CVE-2026-22746",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:737465cf-6e3a-50bc-a15c-5f3455586835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22746 is fixed in version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    },
    {
      "id": "CVE-2026-22747",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:03f2ce8e-9296-53af-8e82-cbb2f6dcbd0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22747 affects version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    },
    {
      "id": "CVE-2026-22748",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:856d45e9-85d9-500d-b4b1-99f400c8a7a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22748 is fixed in version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    },
    {
      "id": "CVE-2026-22753",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1c7e3bc0-caf5-5455-8e27-a69d0bbed442",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22753 does not affect version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas. not_affected \u2014 Spring Security 6.2.8 is not affected by CVE-2026-22753. The vulnerability is specific to PathPatternRequestMatcher.Builder functionality introduced in Spring Security 7.0.0. Version 6.2.8 uses a different request matching architecture (MvcRequestMatcher and AntPathRequestMatcher) that does not contain the vulnerable code pattern.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22754",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0d684c4-12e1-56f2-b1cf-fad4253e3f0f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22754 does not affect version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas. not_affected \u2014 Version 6.2.8 is not affected by CVE-2026-22754. The vulnerability exists in Spring Security 7.0.0-7.0.4 due to a builder pattern bug in PathPatternRequestMatcherFactoryBean, a class that does not exist in version 6.2.8. Version 6.2.8 uses a completely different architecture (MvcRequestMatcher with property setters) that correctly handles servlet-path configuration without the builder reassignm...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-40988",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d767893b-ae29-5ecf-a36a-ebeeebdcf484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40988 affects version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas, and is fixed in 6.2.8-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-40993",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:673ce595-f3b9-5283-a3ec-a484dedcf0d2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40993 does not affect version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas. Spring Security 6.2.8 is not affected by CVE-2026-40993. The vulnerable component JdbcAssertingPartyMetadataRepository does not exist in this version. The CVE specifically affects Spring Security 7.0.0 - 7.0.5, where the JDBC-based SAML2 asserting party metadata repository was introduced. Version 6.2.8 only contains in-memory and HTTP session-based SAML2 repositories, with no JDBC-based implementation for asserting party metadata storage. The vulnerability pattern (unsafe deserialization of credentials from database columns) cannot manifest because the affected code path does not exist in this version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41003",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8e556af-d68a-52ad-bb72-b48a48ed090f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41003 affects version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas, and is fixed in 6.2.8-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-41694",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:11c9c50b-ff7a-5f71-a00a-62b3d91cbb8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41694 affects version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas, and is fixed in 6.2.8-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-41706",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fee9bb4f-ec6e-534e-a465-8e4b285e9042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41706 affects version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas, and is fixed in 6.2.8-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-47838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dcfa41f2-1429-5372-9919-bac8c2a36e76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47838 is fixed in version 6.2.8-tuxcare.2 of org.springframework.security:spring-security-cas."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.security/spring-security-cas@6.2.8-tuxcare.2"
    }
  ]
}