{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5958c28b-9007-54da-9de4-095fa383d631",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "6.1.20-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9859d9a7-4fbe-519e-a143-c2c04c15b478",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5cb5076-579d-5789-805a-9bf186049dcf",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac5079f9-75e9-5b76-8a8d-f19b9ce29133",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a49c6706-7594-5fad-bda4-cc3fbb15a41b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c21ae48e-b2bf-54ad-ad96-6957889732f0",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:053d6f00-8caa-5542-a367-1a4a67c8ec4e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ac4578-6319-5903-b44f-2060a69067c3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab08c2b4-1b14-56c7-b107-0840cad5970f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5866dee4-64c9-57ff-a621-13c345407bdf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86523ecb-473c-5a91-8644-cf15e4ce2885",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50aea436-1176-591a-8182-d49ed0bc3aef",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a72bfb2f-33da-50cd-b9c9-7be808355994",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09cf13d0-e393-5967-9d2d-29611bef26f2",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.3 of org.springframework:spring-beans. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dee7aeb3-d7b5-5556-9ca8-1f85b17749b7",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df4a8e1c-1d10-5470-9630-69873d9d33c9",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b26d699-0574-539c-9526-d003bddc0a3c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42ddec7e-ff93-5388-9598-62d384c532e4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01feb4ec-60e7-50df-af70-532857abdd8d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc7bfa9-2d2a-54b1-98c4-13829dbd5528",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7406d03-4db9-596c-9fe1-56c4803146c0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79875c97-29d6-53fc-be61-c9126f82aeb4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c46dff-d436-5121-a0b8-17e854585ec3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04f6f8ec-67bc-5b09-bd19-c43f48cfb230",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae669245-12d6-545d-bdf6-0b1f33741796",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103ef8d1-8929-5fb2-86c5-85c83f71f325",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.3 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@6.1.20-tuxcare.3"
    }
  ]
}