{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a5ed01fe-1269-55d4-8ba7-c73f9dfac2c3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1",
      "type": "library",
      "group": "org.springframework.security",
      "name": "spring-security-crypto",
      "version": "6.2.7-tuxcare.1",
      "purl": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:aac41688-64b1-56e7-aace-67a9a71a4821",
      "id": "CVE-2024-38827",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38827 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea9e20f5-dd22-5581-b6ac-7f8f2ea48efb",
      "id": "CVE-2025-22228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22228 is fixed in version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:398d653f-28db-516f-bd0a-14f703d09f57",
      "id": "CVE-2025-22234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22234 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd534498-faad-50f7-b695-727c6fe16dd1",
      "id": "CVE-2026-22732",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22732 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a814c974-1c88-5505-ac10-042a6eade046",
      "id": "CVE-2026-22746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22746 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caaf6ead-2c72-5bc7-ad21-0623cf715b9c",
      "id": "CVE-2026-22747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22747 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e2ebdcf-17f3-5d5b-8ad5-6ac33c4fb11b",
      "id": "CVE-2026-22748",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22748 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb8a66d8-a4b6-5976-a2ab-79b6fe612291",
      "id": "CVE-2026-22753",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22753 does not affect version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto. not_affected \u2014 Spring Security 6.2.7 is not affected by CVE-2026-22753. The vulnerability concerns PathPatternRequestMatcher.Builder bean handling, a feature introduced in version 7.0.0. Version 6.2.7 uses a completely different request matching architecture based on MvcRequestMatcher and AntPathRequestMatcher, with servlet path handling implemented via MvcRequestMatcher.setServletPath(). The vulnerable code ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f090e784-762d-5d17-bfd2-060c786dbf97",
      "id": "CVE-2026-22754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22754 does not affect version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto. not_affected \u2014 Spring Security 6.2.7 is not affected by CVE-2026-22754. The vulnerability exists in Spring Security 7.0.0-7.0.4 due to a builder pattern bug in PathPatternRequestMatcherFactoryBean (introduced in 7.x) where basePath assignment was missing. Version 6.2.7 uses a different architecture (MvcRequestMatcher for servlet-path handling) that does not have this vulnerability pattern."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16a8ae52-38eb-51c0-b4b9-86efdf348b41",
      "id": "CVE-2026-40988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40988 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c98685-5807-5a1e-a662-9b87c07ccb01",
      "id": "CVE-2026-40993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40993 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15434031-57b2-5061-aa0d-62989750d473",
      "id": "CVE-2026-41003",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41003 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:167c540b-b90b-53db-b9de-a6d3303a0dee",
      "id": "CVE-2026-41694",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41694 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61199963-14ce-559a-8e00-8d09ebffb8cd",
      "id": "CVE-2026-41706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41706 affects version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05719bda-25f7-5c62-a72d-d255ab480257",
      "id": "CVE-2026-47838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47838 is fixed in version 6.2.7-tuxcare.1 of org.springframework.security:spring-security-crypto."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.security/spring-security-crypto@6.2.7-tuxcare.1"
    }
  ]
}