{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:868ec169-2c4f-50b0-8d69-5047f43c81e4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "6.1.21-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:23301e2a-9b44-5e47-8eb2-59bfe552087e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d8ecfe7-d388-5150-bc80-fc9c3a3259dd",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32a9f2bd-b6a9-5405-ad34-0dc32a47bfe4",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:865ce59b-ed7a-5daf-b05c-3c7f89700697",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8b43b3c-6679-5968-ae8b-fcfdd9548115",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec60a9a-d177-58f0-88c9-2a0e7e30c1b8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82b69ff-b3c1-54f0-b1b9-89c4777fcd33",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcb7967-99b3-536a-a603-724674f0df11",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7ecbd2e-3784-5453-9fcf-17cedd19506a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7094402d-48b8-53ce-b67b-521f9e43e4f7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af9f9b27-568e-5256-9e16-4a7573eac8e1",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a5a3e43-e1b3-519b-a3a3-17be2d8f704c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.2 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3e129fb-8c5f-5aa1-a1c8-c433aaac372d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195533a8-3df1-5520-86ae-5c7009184c3e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a394ea65-443e-5078-b787-a901f1cb46b5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:252c0c70-29fe-5bfd-995c-1edcbf91cf7a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ac8ac8a-f203-5912-b9aa-94b8192a2e92",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98211baa-85e4-544f-9383-e9cc684ea689",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e0f284-feaf-56c1-8f89-2d296a34f3fc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e055a6c-fb57-57bf-83fd-6c79e0069276",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f8b6af9-7390-579f-bbd2-e54dcfa296c8",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fb1f373-f30b-54ce-9f7f-0ab4287515b3",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b14df8-eaf0-5749-b627-47fab91cd748",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e3f0693-270b-582e-9547-a032b918fc13",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.2 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.2"
    }
  ]
}