{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:557d4036-8f59-5e13-9541-bbeaf7888d9a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.39-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:82d333a2-38a0-57c7-b098-c15f55f5583b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15b1437b-8446-52d8-a121-efb14ba4c47e",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.8 of org.springframework:spring-context-support. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a39b1323-1388-50f9-a3fc-0e109d6e7724",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c70a461-5859-5756-a885-ce1be3a972c0",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3941f0c7-38c4-56cf-9430-66544b08b675",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b6da985-bc12-58ed-8a36-5c2ad1be3d68",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3c95a5c-d225-56d8-853d-1151018acc16",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08f8dc81-0ee6-5e7c-9b79-7c76c26e928e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-support 5.3.39-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f4cece1-8c10-5579-9989-84f28c052c83",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a4810b-f81c-5691-a6c0-03cf73885d5e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19932c9-fbba-53be-a158-33d4bc47b138",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e7b00a-d81c-5119-b07a-17e3b5e01293",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f7479c1-4160-5708-a257-03bbbab4249c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796a14a8-97bd-5dd0-acfd-d67c86d7d3ff",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe8037e-7b3e-57c4-a50d-92cd636a97f7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b221aec-1b60-59a7-92da-06dc703ffcf9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a5597a-738a-586c-b3e3-13623699fdf8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71462793-6257-5da0-8b16-c277cd12b1cd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc382228-c775-54e7-a75b-477d445ae59d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.8 of org.springframework:spring-context-support. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ff8916c-85e2-5c46-9e26-cc96d9f1e8da",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c99a1f45-e2b5-50bd-a235-81227b8311d4",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b63372cf-89f2-5659-bd21-c40cd61e9d12",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0398863-53a3-5e85-97ef-19c11ce0a430",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:add928e2-3b35-51fa-95b7-c6d7be6c5e13",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f68321-9947-56a4-bb41-da1144486578",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd5ccd36-d936-51ff-88b1-62cd677ed6af",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b27f1bc7-1ee4-5d97-b1a0-73d47cfad011",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10427aff-060e-52de-bcdb-b971d476d193",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc023e02-4215-55cc-b729-11f0fcf49a15",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be95cb99-924d-5688-bf1a-d8728f2dc8ae",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb5463f-7d1d-524c-b259-94288f6d7c73",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35682153-99bb-581f-a4e8-00696fecad7b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6334b81-c6aa-579e-927d-618317d90353",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.8 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.39-tuxcare.8"
    }
  ]
}