{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9219485a-728e-53fe-b3f4-053eeb295506",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.30-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a027d27b-c90c-565d-9422-121d5fe04ec9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bad32cd8-38f1-5e44-b81c-8264b864dbbe",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899ef4d9-e192-5da6-a309-c88773c3bf56",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd3fe82a-a111-524f-91af-763589ac5ee2",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:203199ff-a220-5961-8ef4-43903162d5bb",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b10fc910-a39b-522d-b1c4-affd1c1d41ff",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1d9aed-9604-5e14-b34a-29cbd9dda0e6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f05a0c-2c95-56e7-b77a-6c328e4e9522",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d22deb3-d3e9-577e-a713-d7b3cf34d523",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c9f9dc0-7e07-51d1-8e61-9c9b83fa6aef",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afb659d8-4659-5d3f-9389-82e29c3930f2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a713de-2da7-5f74-81bc-44343c1aae85",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12628e66-765a-5b6f-8f83-5a0bbc265758",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb558d21-d6e5-5249-96b4-e20c0df6c55a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a30aac81-33f7-56d2-8bc7-9fdee76e4916",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e048ad1-8e00-5f81-a746-3385bfb70aa1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca370095-a636-58a7-bb82-9a36add98184",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df32d945-c6ed-53d5-ad77-7f9e3f9e8dc8",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cdb838c-1d08-5341-a2fa-e11ec1aaa24f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84963dfe-3513-53f4-a16f-93317d867601",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1592e02e-29cf-5545-9bfe-ed32ad523a57",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22444c9e-1296-52fa-9303-519da8cbc2ff",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.5 of org.springframework:spring-context-support. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df4edb4-63f7-5850-82c2-c3d99c4a9f08",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2621948a-d574-531a-b95f-7142e88c2c15",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f440c9-3a1b-5dfb-96d2-e42f62262195",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8562afaa-6780-5556-ae48-a7aaeba9e63d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaf015f3-174c-52fd-a78f-0e8933275c10",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d90fbd-c3fe-5f5c-a660-e8a0f16ca4f1",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b028691-50b2-5536-86b3-d92f94e763e0",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f45fe28d-4cdd-55ea-8742-7e40c22bd1eb",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b3df33f-e29e-56cf-8660-62fd20b4ba48",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:563e44dc-609d-5448-9fce-464c9363c50f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786a863d-c4b7-5fea-aa31-6dd5a5649efa",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a715d8b0-6c58-506f-ba65-256b578db65b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d456db-d128-53f8-9cfb-57590e946e61",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a78a80b-ae43-5752-8ae2-38d076351aa5",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58bffac0-5178-5967-92a5-2da1f64b9339",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.5"
    }
  ]
}