{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:88b1998e-aa8b-53e4-8a80-d8da98fa6ddb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context",
      "version": "6.1.21-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:411ea64a-efcf-522f-886d-9ceefc1900a2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eececf4-c166-5347-b15e-61f47018775c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35505451-ef31-5d6b-8486-7cbd8b7cb878",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3eeff1-9a30-588d-86eb-065d6d34aca8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f27e610e-9385-5d12-8d30-eeeb643b757b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8606faf8-234d-56ae-93c9-f68d7a7d3951",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:381429f3-93f7-5566-81e4-7d23d7b4e2f7",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c781080-0f69-5a18-846e-dc0adfe7a4ba",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39d9028e-0711-5997-96ec-fe630979f6a2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b169911-d0cb-5d08-9082-0b61ac676b65",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fca2555-7303-5e90-b1b1-56be3cf4602b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:496c1dba-21ed-5a9f-ad78-4a4a5e2f48d1",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.5 of org.springframework:spring-context. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f930fb4-814f-579d-9d0c-cdf2c657c773",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d36932d-badd-526a-893f-5ba2dba69a8d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:888696c5-382f-575a-ad93-feddb1789584",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a36970e-0408-566b-8d6f-8f81c9db4fc9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e2972a8-a1bd-5e62-8409-a449f85e0661",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86c263d3-2e8f-5ddd-b602-f592a4aab461",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d10164b1-2ee1-5a52-9c95-80550b061a9b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfe7d671-7ab5-5359-bb92-d634f9c63124",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b7bfdc8-3e86-58fe-9d4c-c5054f96a927",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00156cca-8bff-5d8a-b7e9-865b27d3ee6e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44ea389a-2b9a-5ce7-b088-be05c0dd1dfa",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bebf3a7-bbd4-5aeb-8da1-0dc005196461",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.5 of org.springframework:spring-context."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context@6.1.21-tuxcare.5"
    }
  ]
}