{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2f048474-9509-5699-8039-46b8b622104b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8",
      "type": "library",
      "group": "org.springframework.security",
      "name": "spring-security-oauth2-resource-server",
      "version": "5.8.16-tuxcare.8",
      "purl": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:007519a1-d549-5cc8-b23a-35c3301046d4",
      "id": "CVE-2007-1651",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-1651 is a false positive for org.springframework.security:spring-security-oauth2-resource-server 5.8.16-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3836daa1-d850-5bda-824d-d6953f928fed",
      "id": "CVE-2007-1652",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-1652 is a false positive for org.springframework.security:spring-security-oauth2-resource-server 5.8.16-tuxcare.8. CVE-2007-1652 is a vulnerability in JanRain's myOpenID service, on the OpenID Provider side. The CVE record carries vendor and product \\\"n/a\\\" and a single version-unbounded CPE, cpe:2.3:a:openid:openid:*, and every reference points to JanRain's myOpenID security announcement of March 2007 and the openid.net security mailing list threads of the same month. The reported mechanism - a crafted web page that forcibly logs a user into an OpenID-enabled site, releases the user's personal information to it, and silently adds it to the user's trusted-sites list by way of a cached authentication token - consists entirely of decisions taken by an OpenID Provider. A relying party has no trusted-sites list and no auto-approval step at which the flaw could occur. The openid module of this library implements only the relying-party (consumer) role: OpenIDAuthenticationFilter drives the two-leg consumer flow and OpenID4JavaConsumer wraps openid4java's ConsumerManager. The tree contains no OpenID Provider implementation - no use of openid4java's server package or ServerManager - and no trusted-sites or auto-approval handling anywhere. Nor could this library have been affected when the issue was disclosed: the CVE was published on 24 March 2007, while the earliest OpenID code in the project dates from 20 April 2007 and only reached the shipped openid module in January 2008. The vulnerability therefore does not apply to this library in any version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13eafdc0-11c1-5dd0-adcd-352b27f76503",
      "id": "CVE-2018-1258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1258 does not affect version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server. not_affected \u2014 CVE-2018-1258 affects Spring Framework's ConditionEvaluator.java (fixed in version 5.0.7). The target repository is Spring Security, which does not contain this vulnerable code. Spring Security depends on Spring Framework 5.3.39-tuxcare.12, a version released years after the fix, which already includes the mitigation."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f46e9a6-e442-5c4e-bf22-5da686696026",
      "id": "CVE-2020-5408",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5408 does not affect version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server. Version 5.8.16 is not vulnerable to CVE-2020-5408. No backport is needed. The fix was included in Spring Security 5.3.2, and version 5.8.16 already incorporates it."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3fcebcd-6e3f-58e4-8472-6039b13f8b9d",
      "id": "CVE-2023-34035",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-34035 is a false positive for org.springframework.security:spring-security-oauth2-resource-server 5.8.16-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd82c802-8d05-550c-85f0-9c280079748a",
      "id": "CVE-2023-34042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-34042 does not affect version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server. Version 5.8.16 is not vulnerable to CVE-2023-34042. No backport is needed. The fix was included in Spring Security 5.8.7, and version 5.8.16 already incorporates it."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87fad45c-29aa-5c92-901c-dc9dadb17ea4",
      "id": "CVE-2025-22228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22228 is fixed in version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b088e350-00b8-58c4-9c2c-645fed4a486e",
      "id": "CVE-2025-22234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22234 is fixed in version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a95adbd-87eb-52b7-a1f6-5f6712582f35",
      "id": "CVE-2025-41248",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41248 is a false positive for org.springframework.security:spring-security-oauth2-resource-server 5.8.16-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9897c40-38b5-5ca2-860b-246a93dcab96",
      "id": "CVE-2026-22732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22732 is fixed in version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e8180c-810e-57d3-8442-bce13c4cb0f6",
      "id": "CVE-2026-22746",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22746 is fixed in version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeea2270-4468-55f5-961a-a34a294e1215",
      "id": "CVE-2026-22747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22747 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7bb1437-6d84-589f-95a1-faf961852efd",
      "id": "CVE-2026-22748",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-22748 is a false positive for org.springframework.security:spring-security-oauth2-resource-server 5.8.16-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92ca4f3d-abda-5194-9309-e90c38210946",
      "id": "CVE-2026-22753",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22753 does not affect version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server. According to security advisories CVE-2026-22753 does not affect Spring-Security versions earlier than 7.0.0. This is supported by manual code inspection. CVE-2026-22753 is an access-control bypass that occurs when a user-registered PathPatternRequestMatcher.Builder bean (configured with a basePath/servlet path prefix) is silently ignored by the securityMatchers DSL, causing the security filter chain to match a different URL than the user configured. The vulnerability requires two pieces of infrastructure introduced in Spring Security 7.0.0: 1. The PathPatternRequestMatcher.Builder API itself (added in upstream commit aeb2dbc2 on 2025-08-18). 2. The wiring in HttpSecurityConfiguration.createSharedObjects() that registers this Builder as a shared object \u2014 the exact line patched by upstream commit 438c783c (the CVE fix). Neither piece exists in version 5.8.16."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0523f4f-1568-5077-b16c-cde48ab7a338",
      "id": "CVE-2026-22754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22754 does not affect version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server. According to security advisories CVE-2026-22754 does not affect Spring-Security versions earlier than 7.0.0. This is supported by manual code inspection and proof-of-concept tests ported from the upstream fix commit. CVE-2026-22754 is an access-control bypass caused by PathPatternRequestMatcherFactoryBean.afterPropertiesSet() calling this.builder.basePath(this.basePath) and discarding the return value \u2014 PathPatternRequestMatcher.Builder is immutable/copy-on-modify, so the configured basePath was silently dropped and protected URLs (e.g., /spring/path) were left unmatched by the security filter chain. The vulnerability requires two pieces of infrastructure introduced in Spring Security 7.0.0: 1. The PathPatternRequestMatcher.Builder API (added in upstream commit 3e53cc2c4a, \"Use PathPatternRequestMatcher in config\"). 2. The PathPatternRequestMatcherFactoryBean class itself \u2014 the exact file patched by upstream commit 53bcf0d1 (the CVE fix). Neither piece exists in version 5.8.16. The upstream POC tests (RegexMatcher, CiRegexMatcher + AuthorizationManager variants) were ported verbatim and pass."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e95f5ae9-5028-5680-8bb6-b93efbd40be0",
      "id": "CVE-2026-40988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40988 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a16ea4-313f-5f6d-9035-646107201d10",
      "id": "CVE-2026-40993",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40993 does not affect version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server. Spring Security 5.8.16 is not affected by CVE-2026-40993. The vulnerable component JdbcAssertingPartyMetadataRepository was introduced in Spring Security 7.0.0 and does not exist in version 5.8.16. This older version uses a different SAML2 architecture that does not include JDBC-based asserting party metadata repositories or any database persistence for SAML2 credentials. The insecure deserialization vulnerability cannot occur because the code path that deserializes credentials from database columns is entirely absent from this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1707885a-2f79-5302-b663-0e3550241dd0",
      "id": "CVE-2026-41003",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41003 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9221b031-42dd-5484-840b-a80396f06a38",
      "id": "CVE-2026-41694",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41694 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80655758-e379-54a3-9e81-baf8042bef2e",
      "id": "CVE-2026-41706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41706 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93a1d8c0-3f45-5157-89f3-0f527e62cb85",
      "id": "CVE-2026-47838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47838 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb26a2cd-b12a-584f-b185-a5c0d37f1636",
      "id": "CVE-2026-47842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47842 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9672fc-9702-589f-b3c8-eb4e2112648b",
      "id": "CVE-2026-59270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59270 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8aa0a6-305e-5282-8469-ec57bdc59cd7",
      "id": "CVE-2026-59276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59276 affects version 5.8.16-tuxcare.8 of org.springframework.security:spring-security-oauth2-resource-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.security/spring-security-oauth2-resource-server@5.8.16-tuxcare.8"
    }
  ]
}