{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ffb30c8a-e57a-55ab-8c67-e4b5719a4a1a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.30-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98b04295-d531-5b47-9199-37a0d42ca0b7",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73e1e4c7-3910-5ddc-be66-b007332fa3e5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e702c3a-ceaf-5267-bb31-47b55f2adef6",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b81687ba-eb81-5846-915a-6b0af74c3b26",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab202e4-a2bc-54e8-a7a2-8769e0d84553",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e2343a-a3e2-50bf-98e6-f80e7b8f8ffc",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae8a831f-5802-5574-8559-d163134e2ba6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e9e66ea-0fea-5209-a0c0-e5161bf6030a",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34324468-7106-5b30-a33e-365745860df8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f62e33a1-4ab8-5042-ae12-b7e0e82afe48",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c07b364-40e7-59bb-8fd1-05ab17dc84c3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d19a2aeb-ea74-5bc6-b839-8fbc3d363e07",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0ec26b-7aa3-5a18-85f5-a266e0fce1cf",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cb64743-9cf9-58da-9c5f-6bd9c9fa3e8c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34021410-e92f-5755-a26b-7cdc966fa8a8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3cb6290-d7ae-5863-9ebf-86d47a97d699",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e01c635-cc16-5efa-bba7-1d03131de9a4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c67d316-3ac8-5b7b-90e2-c3ddfd68f2d0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51a52481-046a-5802-b165-b02cb9260563",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91dbdd7e-310a-5d35-b441-703f84b54b12",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5699ca54-bd51-532a-8c95-aa3d6911f4bd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c90899-2730-55a1-aa95-bc99d19ef9e6",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.3 of org.springframework:spring-context-support. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4bdeb1-b46c-50a5-8cfe-35e51854f8fd",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d74e786-fe8e-5ece-a0dd-d084455fa8f2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6beb3811-24a0-5713-b423-9738e9f438c1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c3d26a-596a-5eb8-985b-b197261f9041",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da01064c-c4fa-5e95-a82c-94e16c64d49f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:689f1176-5a86-52c3-85c6-5d269c233f56",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465802b3-43f8-5868-bc94-232eeb596bba",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9713d14-268c-5789-bbfa-3ddac49d1762",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26e9a9af-b683-5492-a997-d50eb8f6f3e9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d55e3d-fa6d-58ad-a532-ccca6551b0dd",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8227165-a215-5eca-bdcc-a1cfc69a9551",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55c6745-e9ed-588c-b815-77a9a74e051c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8fbac9-d958-5389-8d97-5fbefcc504f9",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe54450-63e0-5ce9-9db6-834d9022dad3",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.3 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.3"
    }
  ]
}