{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b64bd86c-5539-5932-88a0-d4e2995dee97",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "6.1.20-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:49e26d04-b7f2-5a2b-8c75-261acdb55dfc",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99a33b6f-f63a-5c7f-9235-c6c1d9180458",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d41113e6-d488-52d7-a68f-83b8b74057f7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d3bae0d-6676-577e-8bb0-e9c66326d803",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d1322e-0328-5082-8464-50903028cde6",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c421fe52-0c4d-58d4-859a-b70c7f9ff7a6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d62f8e3-d821-56cd-80eb-d73dfee60f68",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aafe9d7-b033-58b6-8716-c43f83f2506e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b7df175-9f5c-5eaf-a4d3-8c874dfe3acf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fe330cf-8ea4-5cc8-8155-8f0ddb04a0db",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb03e6b3-21b3-51c3-814c-394fa6af8f7b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83464055-0a75-5a5a-ab09-2733c19d75a4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb0422ae-d636-5246-8d3d-6de93309ea64",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.4 of org.springframework:spring-expression. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7def3377-dd25-5c66-830a-524d35968683",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d9ad52c-b06e-5b6b-a9a2-11004179ddba",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2679e7ce-78fe-5d01-b9f8-bc007b8d499d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e872b43c-2210-5240-8d63-57f38795ae17",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c374893-7697-5d11-befe-3cf0944041cb",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935a2dad-da65-5da0-94c4-582d563e382c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0007a5f8-e5dc-5467-abce-dcc220e3725d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dea8a8ef-756e-5206-942f-725c26fa87cb",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e89636c7-c39a-56de-9733-c1f5b32258f0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6838f3ec-9d34-5d44-9239-25879e0da4cf",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa1776fe-e755-51a9-99e5-1fcce8da02be",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c8961a1-d159-5156-a71d-291b48f48feb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.4 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.4"
    }
  ]
}