{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6466ad69-7ef8-5c6d-b98a-5b11070a1507",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "6.1.20-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:049f2f79-3df1-55b5-a0e6-91609464b765",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f96aa58-9e7d-5368-8c19-3ac4f1db901c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a15eec0-fac8-5649-8579-03864cdb5668",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c5d2021-afef-5407-8a6d-b7e87c368625",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd91b0b5-fb8a-51f3-b460-16c261eefdbc",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36f8781e-e534-5659-9669-98438f4cd96b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65364248-e172-5e9c-ae99-cd428248da6c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa9fb8c9-1d6e-5b04-ace0-67e49a79046b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd7c20b1-86c7-5409-a294-2910a786dc74",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ae5adb1-c7c1-589c-b092-51bf194053ec",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d666f4c0-ee64-5fe8-99d1-5f982b56b933",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9894f4b-701b-5198-bab7-28a440c8d706",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b23af928-66c0-5d35-9464-c11d9320f589",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f83c1ffe-9b37-59ef-92a8-a2b0237f5524",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80aae4d3-d398-5bb5-b8d6-7ef1c995894b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b95e0b1-f13d-5e3e-9437-030c4d44be1a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12090f9c-e63a-5c13-9433-1092be939005",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4f40e52-7d72-5a0c-9f10-e815140a9b72",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8334899-dad9-55a1-b2f3-b214628acaf8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d6ac4f5-e59e-5513-89f9-5acea1bced34",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:617a6361-b95a-5b3f-bad9-7b7fcf346227",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:462e9332-1b12-5883-b578-4649c7905a8a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca842df7-1564-52ad-acbb-0d599d97d7f5",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fb32737-eff3-5158-94a9-97b046dcd6b5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cf6683c-a691-5653-9c1d-0c2bd5044467",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.3 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.3"
    }
  ]
}