{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:810182cb-f09b-5739-844a-6dc97fdff9e5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "6.1.21-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:24f96ef9-dafa-502c-a534-216df9524001",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf50d2bb-00d3-5aee-b6d2-a5c3dd77426f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a0527b0-fbad-525b-90bb-d107cff1d0ca",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dc95dd9-4901-51d9-b025-548d229e99bf",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:969d40a9-bba4-546e-83f2-4c7df7ca9626",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26572152-4074-5778-835c-9e7d278a5cb2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6dad5e4-1a61-5b7e-ac79-8047b6b58ef6",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8cc6be-11fa-5b2e-9d2a-65c62f8ead99",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a6d101-1823-56ee-9fc9-c9a836b61e90",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6257e6cc-6f58-5f76-8aba-b779d8213d81",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:722a684d-67b4-52b9-bca4-925e048bbe8e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b3b39b-5071-5bbd-a8b9-9449be57215a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.4 of org.springframework:spring-aspects. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e744bbe4-b03c-52ba-879e-a87b07a5ee6b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed92a15e-4e2e-5150-bd1d-45fef4096184",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4640b96c-d71b-593d-a037-23d58308ecb4",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8275379f-d724-58d9-842c-6ad9b4ef0fe8",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63050490-59d6-5030-ab6f-ac40e4baeccf",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e31519-7ca1-55d3-92d8-2847359e0ab6",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11119492-c464-589e-b610-c737c1d16a4d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b7ed3d6-7e24-5848-8bbc-4d544e830f8d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea4f6136-7fb5-52d9-9c1b-dd82b1f9e24c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe323d0-b9ce-5c12-9910-6adb9dc27537",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2e27d9-c00e-52db-9f0e-8a20870f395c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7017fe03-3070-54fa-8669-72f95e665bf3",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.4 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@6.1.21-tuxcare.4"
    }
  ]
}