{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:60cb867d-d3b3-502e-bfb6-43e7415c4564",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "6.1.20-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6a2f29f3-7e0e-5c7e-a461-5d204e3a826a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d41b3c6b-14bd-5eec-84d1-3c8e57f6d698",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f138e3b-4100-5c40-a1a1-c37afd84e53b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1866b882-d7e1-5225-b10e-06b8beb320db",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:163719b4-09a8-521e-b2eb-dd228edd7a30",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40a8094a-4e1f-543f-8745-818c73cf8f35",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:398fe9bf-1e4f-5315-817b-a7898f498cbe",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df2897ba-af6c-5178-9c95-f2094a35b6a1",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f6ba46-3332-5b22-89b5-c76fdc5e0e03",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6734b1-67c0-5749-9266-fd37cd2cfb4f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b98c67-42c4-5deb-9e0f-679f3d0c3b35",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c40c487a-0ca1-5635-9e86-e0c7cd48a1df",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52ce93fc-aef4-5497-b246-88f66970759f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaf2293b-cd4d-5041-8beb-3993ec3455ad",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ddfa7fb-7095-556b-ad3e-5fa11492d363",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e648391-4c20-5e61-8323-3cdfb2f5f266",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5f183e-f5d4-5fb8-930c-744f16a1efc8",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce1fb295-c716-59a3-846b-bb5078360ebd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65ccce39-1dd4-5dd6-aabc-a7315c787e3f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35b1bc9d-29de-5fe9-9350-1116fcafd6ad",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc6ef759-592e-517e-bafc-2d9834278ecb",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d18b9560-ecb3-5c9b-87f6-113e45627e06",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fe37b62-9a06-5eb0-bb58-2d8eb2edab8a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bbfe859-b5e8-51c4-b8d4-62073537e180",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd09196b-fb01-5ab2-8663-a685c5ec1389",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.2 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.2"
    }
  ]
}