{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:759d7900-f49a-58b8-86ee-4844bbdab0f9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-context-support",
      "purl": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9",
      "version": "4.3.30.RELEASE-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bbea175e-2c27-56a9-923d-0520e7aff071",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:94bd8739-ab41-537d-b6fb-9c8a90ee61cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1cf1258b-45c1-588f-b90e-19bd29ce6471",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e8434064-9266-5031-8dea-fcdbb62da16b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:84279e64-1c59-5e7f-85a1-172dff43e964",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f2cc544d-8dc8-5c3d-ab06-bf9c8048c4ea",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d211290a-4ecb-53fc-955b-17bd1274d0dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:46be77b1-8229-5c2d-92fc-82da5004b63e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:adf59c3b-d40b-576d-bf78-b7ff5a080e27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:08b94b44-bfe6-5192-8fae-7240fbb0a8c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:24df51b9-6266-53d2-ac55-530d357db258",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8af36bca-3ce2-548a-805e-b90e1f3389cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8cc035a7-52e9-5558-a5e7-0db4ebf36365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8a8340a6-79be-524d-b45a-9ade8dec7a3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:caeefb70-e384-53f4-9f02-6350879adc85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7fade6ed-f675-59c7-ae52-f146f00e48ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:374e9caf-3cfb-55f0-a7b0-94caa02a6265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d333c4e0-b24b-5d9e-8d84-8af3b2cad5c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cb2f2ef3-e315-5107-9275-098083feaa0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3416ad29-d820-53cf-a541-9551a9c8e644",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d571ea4b-a8ad-5aa1-be97-db450d66ef72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9ffe73c4-06cf-509a-b961-eaf77da89408",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dbeebe7f-358d-5531-8ef8-c3d7744a0fa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9dea6ff1-2e65-54e6-930c-670aac65d596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:aeaab8ac-530c-57e3-92d8-30f84b4d6a24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:65cf63f9-0bf1-5be7-81a7-1f3fb0d0016a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0847578d-6b5c-5deb-9108-faa400afe0e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0a13d239-ad2c-56e0-b5cb-d018eef36626",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:01e54a5c-4a1f-5012-b006-6579f6d845d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:75378d00-e90a-5c8f-9dd9-d601e7e0acf8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d674abf6-9a66-58d5-b0ae-4308db739c90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7f34f099-2a98-5d8f-b050-abe058f15226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9f4e260e-217a-55fc-a691-51ff54fc6030",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:47da910e-69a4-5981-b81d-5e575dec2267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:57748785-cd94-5fed-818a-024d7534a61c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:48201399-2b24-5423-9caa-3405f80249f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bf8184c4-7d4f-5ca5-a9dd-63e8edc5a140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:393b6357-585b-5b9f-8afe-24955db5e022",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d805c7e5-6709-5af8-9717-a1fad7959b85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f4e4930d-7e67-55ee-ab98-a5befcbe0501",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fc38ba65-e7b7-51c4-832f-7dd6b4380752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9c3beb8d-b57f-5820-b67c-6b3de216aea0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e3c7f50a-2d42-50df-bb0d-738c07281252",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ea035145-f35c-5570-b587-fb7bc81be3ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:32ce41d6-f814-5135-b541-861717242e4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3607129d-01b0-503b-97e7-058027a2fec8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7afb54ec-21c2-5b54-80c8-3d9c0047d3bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a59b196e-dca5-55e2-ad2d-3f8cd04bfe8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:53469b59-d297-5fa8-bc41-ebbce9a76f05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0e9ee0d6-56d0-5951-9fb4-57637ea01fbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7ac35c22-96f4-50da-a9fe-fd388b8d2087",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:da12da41-a2f5-555b-94f3-bb1f95765217",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a621c129-1d89-555a-a20a-937af33918a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-context-support."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@4.3.30.RELEASE-tuxcare.9"
    }
  ]
}