{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:31847ee7-6cb3-5b06-b67e-85e653b41325",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.31-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5a197069-7d9e-530f-9894-2938911ebb43",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd8a38a8-cafd-5edc-8e43-fa9eb7971ce3",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fe23dde-f9a4-554f-a09f-72cd3f219232",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a1172c-c9e4-5dfb-aef5-9d6c1b18a6fd",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29b8f299-44ef-5b9c-a121-1ec211684422",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51008ceb-4232-5b7b-b0f8-c9b4bf5a7732",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0df805b-108f-545b-8bfc-eb1346bde874",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad715f9a-0ed4-57df-b79a-f3e7154fb78a",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5dd4a7f-011d-5280-9210-ae2e25e91e0e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:163abf62-8066-5e26-956d-16af15dd41c7",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:120121a9-1976-59e1-aa28-fe8af22e12d8",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edc52404-9e50-59c9-9ad1-db6e7216e00e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-support 5.3.31-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53570bc1-5549-5afa-b66b-e9a101b00daa",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4413e522-8e99-59de-aa9d-3126cd2087e1",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d8b7a85-c85f-5589-b63f-fa641cc14bee",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e5b410-f5a2-5b40-abee-048e7a43c8c0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0176a3a6-4999-5680-afc3-07275539c94b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:900fa71b-bb2a-5eaa-84ff-ed8f1ca1a806",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4d34f52-874e-5d8a-ad39-83892284c7f0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e09375d1-4f34-5f31-b7d9-b44989fe1bc4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5c07840-72b1-5e66-88ea-db9c3eda15a9",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5618d9c4-5d3d-582a-8d5d-ed5a1adc6672",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b29cbb37-8c03-579c-b3e6-f0fa15768233",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.3 of org.springframework:spring-context-support. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67697ccf-963a-59de-9959-228a58d65121",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbdd6d90-c508-5431-820e-220b17d97313",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ab7baf-3f66-5724-ac7f-71ef54834f75",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b73f3d5-4c3c-5cf3-b20a-97349e216454",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab9f86e-43f4-54eb-a135-d2b17f74f4a0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293e078c-3f5e-592d-8bdd-1ef758e5f560",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acd6bac2-55d3-5723-9bc7-0250d327eb2a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b4f5683-440d-5a46-a4c3-ede178e7f122",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f57e8d4-29dc-502e-aac7-6260c157c715",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7a2ca87-69b4-5770-8251-2b804ff78c73",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:141b2ccc-5576-5d30-a79d-660a74191ef1",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15930532-84f3-5cfe-8313-40267c92c7ad",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d29c644-d508-5c9b-bd8e-3452befb684e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c1ab3b-e4cb-50d5-88d3-dc5f610faefb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.3"
    }
  ]
}