{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d8d54b3d-277d-5b53-a517-5f9482e2419e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7",
      "type": "library",
      "group": "org.springframework.security",
      "name": "spring-security-config",
      "version": "5.6.10-tuxcare.7",
      "purl": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b0ca6763-3e71-5f8c-8b80-c46d54b44bcc",
      "id": "CVE-2007-1651",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-1651 is a false positive for org.springframework.security:spring-security-config 5.6.10-tuxcare.7. False positive \u2014 OpenID CVE, not related to Spring Security. CVE-2007-1651 affects OpenID Provider application handling of cached \u201calways trust\u201d authorization. Spring Security is a relying-party consumer; its DISCOVERY_INFO_KEY cleanup only prevents reuse of local callback/discovery state and does not address the provider-side forced-login flaw. No upstream evidence identifies Spring Security as an affected product."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8537669a-18dc-5fc5-959b-16947839bad8",
      "id": "CVE-2007-1652",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-1652 is a false positive for org.springframework.security:spring-security-config 5.6.10-tuxcare.7. CVE-2007-1652 is a vulnerability in JanRain's myOpenID hosted service, on the OpenID Provider side. NVD records it with vendor and product \\\"n/a\\\" behind a single unversioned CPE, cpe:2.3:a:openid:openid:*, and every reference points to JanRain's March 2007 myOpenID security-fix announcement and to the openid.net security mailing list of the same month, where the reporter states the problem had to be fixed on the myOpenID server. The reported mechanism - using cached tokens and an existing Provider session to forcibly log a user into a site, disclose their personal information to it, and add that site permanently to the user's trusted-sites list - is Provider-side behaviour; a trusted-sites auto-approval list exists only at the Provider and has no counterpart in a relying party. The corresponding GitHub advisory, GHSA-3x88-xvgr-m6fg, is unreviewed and lists no affected package in any ecosystem.The openid module of Spring Security implements only the relying-party (consumer) role. OpenIDConsumer and its single implementation OpenID4JavaConsumer wrap openid4java's ConsumerManager to begin and end a consumption, and OpenIDAuthenticationFilter together with OpenIDAuthenticationProvider turn the result into an Authentication. The only openid4java packages referenced anywhere in the source tree are consumer, discovery, message and association; there is no use of org.openid4java.server, no ServerManager, no OpenID Provider implementation, and no trusted-sites or \\\"always trust\\\" handling of any kind, nor are any openid4java sources vendored into the tree. Nor could the library have been affected when the issue was disclosed: the advisory was published in March 2007, while the earliest OpenID code in this project was contributed in April 2007 and the openid4java-based consumer only appeared in July 2007. The vulnerability therefore does not apply to Spring Security in any version, including 5.6.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25c62ebe-8fc3-53a8-9bd9-1a0207d67be0",
      "id": "CVE-2018-1258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1258 does not affect version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config. not_affected \u2014 CVE-2018-1258 affects Spring Framework 5.0.5-5.0.6 when used with Spring Security. The target is Spring Security 5.6.10-tuxcare.3 which depends on Spring Framework 5.3.24-tuxcare.2. The vulnerability was fixed in Spring Framework 5.0.7 (June 2018), and the fix is present in all subsequent versions including 5.3.24. Spring Security's own code does not contain the vulnerability pattern."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35362478-efb5-5eed-bc8a-b0528a7f3eca",
      "id": "CVE-2020-5408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5408 affects version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b56f210-4114-5102-a0e7-30dcd419216d",
      "id": "CVE-2023-34034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34034 affects version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17dd38f9-c2a4-5052-a1fd-2c509594374e",
      "id": "CVE-2023-34042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-34042 does not affect version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config. not_affected \u2014 Target version 5.6.10 is NOT affected by CVE-2023-34042. The vulnerability involves a world-writable symbolic link (spring-security.xsd) that was introduced in later versions (5.7.9+, 5.8.4+, 6.0.4+, 6.1.1+) but never existed in the 5.6.x branch. Analysis confirms no symlink is present in the target's source tree, build configuration does not create one, and git history shows the vulnerable sym..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f6f0ce-5e29-5ffa-b97d-3eb1a3cd918b",
      "id": "CVE-2024-22257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22257 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3db3326-8393-568b-8ef8-127e92532680",
      "id": "CVE-2024-38821",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38821 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb850de6-0074-575e-ba45-5f7b13feed81",
      "id": "CVE-2024-38827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38827 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb569bd1-851a-5a26-a3cf-95765a3a6cce",
      "id": "CVE-2025-22228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22228 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14dc1b65-5168-5b50-90bd-70c3e4a0e98e",
      "id": "CVE-2025-22234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22234 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6da58a00-15f5-5ee8-88c4-0a8c99307e5d",
      "id": "CVE-2025-41248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41248 affects version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366dab90-8fe0-550c-8278-647af0bb75f6",
      "id": "CVE-2026-22732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22732 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc06e4e7-30f0-5cad-acb8-09d684313c51",
      "id": "CVE-2026-22746",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22746 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3274f206-d274-5bf5-90f6-6490d1193ad4",
      "id": "CVE-2026-22747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22747 affects version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad10dfc-a735-5cd0-89b9-35566eacd5a1",
      "id": "CVE-2026-22748",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-22748 is a false positive for org.springframework.security:spring-security-config 5.6.10-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e0d3015-bd64-51c7-9394-8c2db25d5533",
      "id": "CVE-2026-22753",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22753 does not affect version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config. According to security advisories CVE-2026-22753 does not affect Spring-Security versions earlier than 7.0.0. This is supported by manual code inspection. CVE-2026-22753 is an access-control bypass that occurs when a user-registered PathPatternRequestMatcher.Builder bean (configured with a basePath/servlet path prefix) is silently ignored by the securityMatchers DSL, causing the security filter chain to match a different URL than the user configured. The vulnerability requires two pieces of infrastructure introduced in Spring Security 7.0.0: 1. The PathPatternRequestMatcher.Builder API itself (added in upstream commit aeb2dbc2 on 2025-08-18). 2. The wiring in HttpSecurityConfiguration.createSharedObjects() that registers this Builder as a shared object \u2014 the exact line patched by upstream commit 438c783c (the CVE fix). Neither piece exists in version 5.6.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db3ade35-a640-5e74-aef3-e56a3d31c07c",
      "id": "CVE-2026-22754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22754 does not affect version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config. According to security advisories CVE-2026-22754 does not affect Spring-Security versions earlier than 7.0.0. This is supported by manual code inspection and proof-of-concept tests ported from the upstream fix commit. CVE-2026-22754 is an access-control bypass caused by PathPatternRequestMatcherFactoryBean.afterPropertiesSet() calling this.builder.basePath(this.basePath) and discarding the return value \u2014 PathPatternRequestMatcher.Builder is immutable/copy-on-modify, so the configured basePath was silently dropped and protected URLs (e.g., /spring/path) were left unmatched by the security filter chain. The vulnerability requires two pieces of infrastructure introduced in Spring Security 7.0.0: 1. The PathPatternRequestMatcher.Builder API (added in upstream commit 3e53cc2c4a, \"Use PathPatternRequestMatcher in config\"). 2. The PathPatternRequestMatcherFactoryBean class itself \u2014 the exact file patched by upstream commit 53bcf0d1 (the CVE fix). Neither piece exists in version 5.6.10. The upstream POC tests (RegexMatcher, CiRegexMatcher + AuthorizationManager variants) were ported verbatim and pass."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5775a2a8-3e5f-57b4-a66f-0a7fc7898fca",
      "id": "CVE-2026-40988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40988 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea0ad74d-3220-5ac8-837c-1fb80201aaeb",
      "id": "CVE-2026-40993",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40993 does not affect version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config. Spring Security 5.6.10 is not affected by CVE-2026-40993. The vulnerable component JdbcAssertingPartyMetadataRepository does not exist in this version. The CVE affects versions 7.0.0-7.0.5, which introduced database persistence for SAML2 asserting party metadata using Java serialization. Version 5.6.10 only provides InMemoryRelyingPartyRegistrationRepository with no database persistence or credential deserialization capabilities. The entire architectural feature (JDBC-backed SAML2 metadata repository) was introduced in the 7.x series and is absent from the 5.x codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e591ad0-242d-5e2f-9bca-d2f050f01207",
      "id": "CVE-2026-41003",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41003 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f99c57f-e5ae-5853-8c5c-03655fc419e8",
      "id": "CVE-2026-41694",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41694 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d1f196-c3cd-52b3-bcaf-0f6c13489ee4",
      "id": "CVE-2026-41706",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41706 is fixed in version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:515cb9df-3ae6-5c2c-81b9-3f4f43e3cfee",
      "id": "CVE-2026-47838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47838 affects version 5.6.10-tuxcare.7 of org.springframework.security:spring-security-config."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.security/spring-security-config@5.6.10-tuxcare.7"
    }
  ]
}