{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ae9ca406-d1be-52a8-98c5-1eabd9a8dba0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "5.3.27-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0a8fbdb0-ce39-5130-8dda-96cb7db9190e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bee77fa2-4b1c-59e5-a975-cdfeca9f1975",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9193c28a-b572-5806-bdf3-249b8602c631",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72762bf4-87c6-55ce-9e63-02de5d2319a7",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1eb8569-ca53-5731-bd03-33987df3bd02",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b2b08cd-c733-57c7-ace5-33e6e803a4f1",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f95757f-8c54-5f94-b503-08cc27219417",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c872978-2087-5d23-b69a-9f0a2bae78cd",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d27b8da8-2081-56e9-8856-766113deefcc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b839378a-5f39-5fb9-81ae-b56a76957637",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bbd2393-2e5a-5cfb-b086-074ddbdfe5db",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:263af02a-eeb7-5e02-baa3-0a3f3e9c0518",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-indexer 5.3.27-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08e441b0-98c6-57c5-b5ab-b23740ca1af2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ae585cf-626b-516c-9326-8eb5efba7567",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:805da62e-d813-5abb-b14a-654d675b2005",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb567cc-185f-57d5-853f-f059e4b7de3c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8fd51a-8bbc-5edb-a137-1580eb4d3cf6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7867074f-3833-5c3b-89fe-30db99ed80bb",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd9b4a6-2d2a-5dea-b4d0-d8a11067e42f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556f2d7e-a26a-51af-8c1f-c37236b8bb23",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3659d7f-1799-54d5-bb9a-9277dfe8ebd0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bd81d72-0eb1-5bfc-98be-1973348586bd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9abc1752-fd4a-5316-aec7-4d657ff4df8b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12d6130-f75c-50ad-b93b-36398a39f7e7",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1c26c2-6ee4-5326-b4f2-524f91381b4e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4091036f-015d-53ff-a6a0-14eba630c944",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89c1e576-724d-5e82-996a-16cfafa2720b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7451311b-16db-524f-8c0b-d461fb3340e0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9826c0f4-2594-5943-aeaa-a4ab9646299e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:987df920-a157-5b43-9abf-26314cc428fd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6934147-4322-5830-8f3d-3b44f2145d0a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:290bb2ca-72c5-5e38-bd46-f4e1091fab26",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915b120b-d3b9-5000-96e9-083c105596ee",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6552f5ea-3bd1-55aa-8dbe-278acf84b999",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35e2ce5d-c62f-505d-845d-32849d9939f1",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4784bdc-dd56-5000-9837-3f7efed1cf43",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef0ac60-8b09-54a1-bcfd-31eb7d0c94dd",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@5.3.27-tuxcare.5"
    }
  ]
}