{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0a17e662-5996-5a28-9f37-bf09cfbaaa2b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.30-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bf1d4bb5-43f7-54e2-928c-7524f2e8b440",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ab1e566-1e33-5529-9eda-a4baae7047ce",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca7546d6-f3a1-5d17-aea6-50e05b53aae6",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e96229e-2b17-5f6b-8e7e-8a6f342ec2bd",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71dad305-eabd-564c-bc6b-723fa7e83cea",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45388710-3225-53f5-be14-808883ec44dc",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cfaec29-c58c-51e3-b963-bafcc3be3e77",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d396f25d-7a5d-592a-b1c1-c3088d8bc2bb",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9126d7-1418-5064-baa1-cd9fbc02a170",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6772d478-d485-5ebe-9553-b6d37a857d16",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6805cca-1917-5799-a7cb-d7916149c334",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd9fa87-f3d9-53ee-8694-bbf74c1c0adb",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0271e98f-457b-5223-9810-deb3dfeee2e8",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:651ec130-30d5-5df6-a855-283c936e519c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d00f72-5270-5de8-8e93-c54e5ff6a1c0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aafbf29f-bbde-523f-96e3-b113a7be33ad",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11999e93-d9ef-5d57-ace8-7d46e3bf6847",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec74a66-307a-5e3c-b59a-2cdc943aba78",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa611f49-7974-5f0e-943f-fb102bf903cd",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2add7292-62d5-597b-bbb3-447cb8b8f12b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:809e99ae-aa5e-5b6d-9dbf-b0af0c0a3343",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9c21e13-3acd-592d-821a-37e12252bcfd",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.6 of org.springframework:spring-context-support. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02d7c396-2cc7-5f58-8332-1793106fb161",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff040922-6401-559e-ae06-55b29c47ae21",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04391da9-0b45-51f7-80ce-0d6e99e3295e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9e5522-a39e-5111-bd48-6dfa2090efd4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3647d9ad-0c3f-541f-adf2-35048bad2b02",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:918f2c42-bf41-5dcc-8ab1-91ba56cc7597",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be6679e5-36c2-5369-8a4c-91eb10111440",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57b88824-3e27-5a50-aca6-fa2c8f62a0c4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f264d338-466d-58f6-9f2a-78f5c5732ef5",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ade70787-91d1-52fd-930f-de315dc2b1db",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed64cf5b-998f-557e-9028-e72ccbf0f54e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23aad55d-ea84-59e7-87c2-ec03e0d731af",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:335cb0a4-aa8a-5b3a-83fb-66be962f7265",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d09acd65-efaf-5638-a5e7-c97af212f169",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79901ae-1160-555a-b3c7-d82b30dab854",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.6 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.30-tuxcare.6"
    }
  ]
}