{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:438ccafb-db6c-5da2-b59b-b7c86e59f2c0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "5.3.27-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c01a998d-87c1-5d03-bb68-1f206c697d7c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:742eeae1-7e61-55ab-871b-de1598e4c3b0",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af063168-0f1e-5c67-950b-a3bde21b0b9c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:357a7390-c553-5115-8805-3fa3aa92d4a0",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d0bb65-8c77-5504-a279-7178e019984a",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0adbc66-e4d3-5255-bdf1-2d0db0c36e2e",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:684043aa-aefb-55a0-9ded-07809e416935",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:333935d6-c37d-571e-883b-700bc37181ce",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4d6ad6-ea1a-5c61-84ce-d0afb381710d",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d590ac42-78aa-509b-89c9-30159dade9ae",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e72052e-bcb9-5df3-a461-e6992c038cd9",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cafcc8f3-69fc-5830-8bc6-1342cb60119f",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-indexer 5.3.27-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d625f17-dfe9-56a2-8326-88580538f541",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b26216eb-0a9a-56d9-b124-a383f316bf39",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f70284be-2777-5f5f-8c91-79e1899e2328",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2ac6de-32a6-5232-99aa-26bdfac5c170",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f1fe220-298f-578c-b93b-cbcc6f63a613",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d094076d-e551-54e1-ab1d-4bff54499770",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d010a2c6-af90-534b-81b0-d3cccf790573",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a02ac1-ac1f-5db1-9fa5-345f1e513224",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db4debdd-e961-5166-a1ec-752bc8f9b03e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3248042b-4b0b-546c-b855-3233519a79a2",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da00488f-2032-5f2b-a72c-83a7ff938109",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:104b210a-13d4-5d87-b73d-c0f989a6f2b2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76ff0163-7242-5428-811e-68194a6eac0a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:931ded1f-21ba-5061-8eb1-2f5cb23935c8",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a29878ca-7648-51c5-b657-059c6c31b191",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde860d5-cb55-5b0d-b82a-18a96f20ced5",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edd2c816-5d8d-52e3-93c2-e5f76ce2a4e9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fe04edb-b522-500d-838b-06f4c81efa53",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94df1792-396b-5d5b-8838-e65c6f238666",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d60ed9c1-d2f7-5dff-8a83-f8520e45ead9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64bb29b7-8b7a-56cb-b12a-dec8c1383cc4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c59310b7-92fa-5728-be70-68f7a97ac1ca",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ec6d1e-5411-5bec-9b87-34de1e0ebd66",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15d60b55-ac8a-52bd-9736-2ee78957fd81",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4182fa6-b613-57b2-82a0-077284c8fddb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.4 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.4"
    }
  ]
}