{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0136a8be-6931-5f9f-a51d-cb46ee778cf7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "6.1.20-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0d8efc36-9d3f-50e8-b4c5-dbb55127c68e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-context-support. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c9e457b-1bc6-5676-8d0f-a3600ab8b4d5",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26897bb9-45be-52b0-9e2f-060e777244cf",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ecca388-ce48-5bf6-b23b-b1c1b2c2a4f5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2f33859-2323-56ac-979e-2e3c6bd93745",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94d450c5-7c03-5232-ab62-cca7bfe6a0df",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aba4e3be-7cd1-591e-9d73-bdaeb75f036e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7598749c-75cd-5d84-bee0-2ee4b201e89d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67d7cb74-18e5-577a-b313-7fb4da403f93",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7fcdba1-c246-53b0-9913-62cbec4b1cf8",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1375bc46-45cc-534f-be2b-ef01571fdc9f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ffb8b27-aaec-503d-af9d-1e49fc0ddc71",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e73755a-2d78-5f89-9367-bc47714573fc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-context-support. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d883134-2a9d-5c79-b1e0-4bbb8e368328",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:209f0c70-4aa3-5632-a6a8-a634c485acc5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee4edb5d-15d7-577d-99dc-f3044b598e1a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22d1737c-827f-578e-8ca1-e3cb234a6924",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46bb0d5f-51fc-5ed9-8e75-7173897145bf",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd84f8a-8ba8-5277-8481-64c2b084ea28",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edd174c4-3bf8-5af5-afe4-eb0ac3829c7c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a0e600b-e59a-5c38-9bb6-d25ed18d6491",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd639b8e-1426-5dbd-a402-8ba194469aed",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67101208-9528-5414-a6f6-a9c1d3baf526",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc820229-f9d0-5e2e-a2b6-e41040d195e0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a61a721b-c2bc-57d5-a4fe-b164d4c0e817",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.7"
    }
  ]
}