{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7b942f7-3422-54bb-91de-7cc30fd9c81f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "6.1.20-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:79de57dc-84bf-5f0a-ba8e-88738b76c307",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48ac3462-9566-530d-9fa9-f0301096d140",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83e52ce5-2b43-51d7-a1ea-7027fea28e7f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a66dd5e-8f1c-55bb-ad2f-8cf49b960942",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:346ef9ee-1e18-597d-a6f5-18aec4f2be89",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a5c708-aed1-5d8a-ad90-2120a65b61c8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d9075a-fc9b-5cca-9667-1406e07dcbd9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eecb3b1-b6d2-5974-9ce1-68d829411ffa",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f88dd8e2-b57c-5937-886b-99a11479978e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42b093d-06d0-5c72-b6c9-2d9edc612828",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a835ef-197e-5155-85cc-8c88c5b20347",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aa7ff11-06cf-5e38-8022-5b24f58d2d09",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085b0ab8-0fa2-574d-a9a7-f058ad0a5e45",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.4 of org.springframework:spring-aspects. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e05841ee-2758-57ac-b286-f6363eb13d8d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e62708-0b7b-5aa3-9023-32bc1f91689e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc8a963-ed7d-5977-854c-d17e228a3c4e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:707f57f1-a38b-59e4-afbf-5df5424b9591",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59377cef-2547-5be5-a32e-fd495b4368e3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:839f3148-3d7c-5ab9-8f44-232433bd3328",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c9fd006-8ac1-5eb1-9c7e-46317c24a10f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b87ab70b-b4a0-5e7b-b619-2bc40196f529",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1934941-fe1d-5309-b479-793900a481f9",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c5aa6c-1558-5a0e-bbc7-5bf86b1cf51a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:453be453-6f3b-5bbd-9144-5aaa087db98c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b570f9e-edf0-56c8-8805-6adc26253302",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@6.1.20-tuxcare.4"
    }
  ]
}