{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9658eaf7-1471-5a05-bd3e-a1fb4780b837",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context",
      "version": "5.3.37-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:47396c0c-1aae-52cc-a819-75e24f0e6632",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53f973a5-48a2-537d-a201-71b4450d1d5b",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1e8d1a7-e366-5f65-a24c-ff21ae5bd641",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa577bb9-b325-5829-8556-cc922270fb08",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e904eb2f-752a-5220-96af-f8b737a61192",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab1299a2-1a23-589b-8f3d-0765d3d1944e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f2b1b8-2907-555e-9326-bb4a727dc431",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9507475f-686a-5379-b45b-20fc92eff47e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d5de809-20fc-5917-a98a-fd277d9d4a1c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6290483d-817c-5210-b05d-127b94426ea6",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06566429-1ba7-57e6-89c4-a9743cc887fe",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1b8a2c-89c7-5ab7-9f11-fe755aebf2e8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac941d86-dd99-505e-bd36-1c8cb6556ed2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39b7fab3-3928-530c-a1c3-899825c55cab",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79ee4978-bf3a-56bc-baf5-9a1f570f0ff3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f018fcf2-4068-5aaf-9807-52112b55c969",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0e7a219-f01d-5d5a-aa44-73abf98a7d9a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9935493f-dc7b-511b-918b-b5b8506633ad",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a5b669d-d45c-5c6e-b3dc-1f1bce1305ef",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.6 of org.springframework:spring-context. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef4fbe2f-81c8-592f-b1f6-f1b6bb3ecbb0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:168ee393-bc0f-5c6c-9f81-24c6e3a399f6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:428cc177-8a6d-5498-9499-c735046f6b92",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c666a8ad-9016-5509-8ab6-5a99e294218e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72521642-b6e6-54b5-91bd-7331c54c5310",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1930c9ea-b6d0-529e-b820-16755f10e6fa",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:265c2a42-e3db-5072-b809-db17a1af5156",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:327c80ab-c9a4-5c02-88c0-b24a10a22191",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e2ed06-01e6-59d1-8977-44585cbb0248",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f1a2732-33c3-5e2a-83be-f6c5bfa774a0",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ebd78a-2ef1-52ca-bf11-dc316dd0c1b3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac4119b8-55c9-50d3-9355-3d062a68db49",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca78f4b7-8bab-5469-ae26-f4d094cff827",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d149d7-915e-521f-a57b-a6cc1aafee9b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.6 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context@5.3.37-tuxcare.6"
    }
  ]
}