{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a017ef21-ff6f-5e76-ba43-5d241e051147",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "5.3.31-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:66c68686-207d-54b0-8892-8d5a9e8fdc9a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:111f492e-95b3-503b-968e-efdd951ba79b",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ca1a9b6-c546-5ebb-91b6-8bf5098a00e0",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51956570-34fe-509c-8d12-25c5b430066d",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b8a95a3-3043-58e9-b107-fe1875592779",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23dd949c-af43-56ca-b9dd-d401d237e668",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745168e8-c6d1-5f18-847e-73b2085c2310",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4adec2c-9870-5aef-a416-6b21ff29163b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86c36e6-6aa0-59b6-bf69-4b5b952ea9cf",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40156aed-48df-5711-a8a0-87ff7fa444d4",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7426b1c6-1cbc-5828-8ea2-4b2fd649ea35",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2a363e8-f7b4-50c2-8786-3c8b99a86f39",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-context-support 5.3.31-tuxcare.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b27cc4d-bceb-5492-9484-ba713d949d6a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ffc6c9a-4ec3-5186-a24a-9a41d70a5199",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:508b86ad-8c81-5949-b6bd-044adb6e8ea8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bd996d2-ddb8-59b2-91dd-725b3cf00fba",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde516e1-5ee7-5a22-8086-9052e316a3a4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc935cf9-b139-5801-941a-93f00ff59f71",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8a41f3-d829-5ac5-8e73-06f20a49eb73",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb4959f3-f5bd-5598-a05a-e0db0f696e9c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94fca33d-d5b4-5400-8d67-73c1fae75a14",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bf315c1-9d00-5be1-9aab-986617ba02f7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4808b07c-2c90-59fa-b671-d5f7ead28078",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.10 of org.springframework:spring-context-support. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c67668cc-8aa2-5f7f-88bd-781097547fbf",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eda0dec-8d39-5ba7-8de3-344416f5dc49",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e11ca82-ad47-57bb-873d-aae514fe132a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8173ab14-e1b8-5768-beaa-d98a69e6fc0f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea749f1e-8b03-5cac-ab8b-f366ef9ad97c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b07aa27-9a0a-56a6-abe5-1818b308fa11",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa0f738e-c6c0-5419-88f6-2859bee481f5",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d599525-b469-5123-ae08-39b14c37dcfd",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8d88b0-4ee8-528d-9334-5f06215580a5",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5bcff71-f1cc-516f-b438-74ec80cc6e53",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bf6ed32-f1dc-50a1-ba83-b771d6ae36c2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51ee3bb-64f8-558f-b331-f30f6a87fa24",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1905a1d9-5c2c-5ca2-b7bf-a3ac4277afd5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33f5e5a-d5ef-5e01-ae10-df40023c8ddf",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bfcd33e-148d-55f1-92e1-290c3b010651",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.31-tuxcare.10"
    }
  ]
}