{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5e99861b-d2f3-567c-b60f-84fbd5498bd1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "6.1.20-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3c992f63-5f6d-5d3c-8e35-531263005064",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b155325-9b7a-52ff-8ac3-197127b03cbb",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36191695-2877-5acf-8d63-6a6141e0a31a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd5d076-afd4-55ac-909d-06efcf91e7ab",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58a0a8d5-9178-5904-b6f7-682d3ceeb478",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14d5f289-2be6-5853-824f-daf238eb7efa",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0201192-22b9-5475-ab36-d5d8ae1475ee",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81e0dda-021c-5382-8116-7dbd07e793f9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0f517ae-619e-5d27-a1e4-9e12279ffe8b",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d9c916c-798b-51c6-8e67-b26454535553",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b045bc9-2be1-5563-a3d9-752c5577acac",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a8738d-2adc-51b6-bd6c-5d1770f5c841",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:280afa31-211d-5e74-aee5-ee3929f78286",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0d1775-bcda-5b42-8b53-0dd0533745cf",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffe2fe4a-08de-5198-b79c-2b75b7b28715",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb2bd53-d1fb-5e8a-b146-2de7fe0cff4e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69787c88-78db-5e65-9a9a-dbfcba38693a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1fd182-fedb-5d06-91ad-e0e9d6f4222c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84d9d92d-4bc0-5b83-8bbb-6d1dd8813d58",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c879406-a84e-53bd-9066-9cdef3ea10c6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb36ef0-9752-5991-881e-9be61c8d0089",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2568548-3382-5c87-9122-e215fe5942db",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c70cd1a-f2ea-545e-9eb9-1bbdafacf4b9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:155e0f8b-8f4a-5fb3-af0f-fb1946ddd819",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:132e90bf-274b-531d-a010-316cfd6a1dea",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.1 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.1"
    }
  ]
}