{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2c1f0213-7442-57eb-b004-09c7d0bd6c92",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "6.1.20-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f7f9746d-a39e-5af1-83f5-f8b32174711c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-expression. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613b70fd-310e-5258-9952-63588a283473",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04420aa7-2670-5d88-a157-976540a67b49",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0f135b4-4115-5989-8c23-ebec1bd2d7e0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:191088ec-15b1-599d-ae22-4c3ec7be0258",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16ad9f21-32c0-526e-8b8e-49d5035f21df",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f51a57-5515-536b-8297-08e67c4533c8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:505cb65a-699c-5aea-85b0-204e2c570397",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a506e75-bc20-55ec-9854-9e5f5cb2680e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc1010ca-56af-57aa-8aa9-be773c644804",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3b58567-a576-5b46-8987-7febe1f0964e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a40427e-3991-5e06-9811-4f7a0bae3c8c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03025a6e-40c5-56a9-82dd-58ac9e074148",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-expression. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d56f28f0-1de8-5fe0-86f4-0f061b6e0ab8",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11b42d1b-d4bd-50b2-bb8b-89b3e070e325",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82f45b3-2b2b-5c29-a954-737c1372a217",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb86df3-93f6-57a2-a8b4-a8e17d4a468a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0bf9e5-2679-5eb8-bbdf-6625d5862fde",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3d511b5-aa12-55d9-ab5b-2c9ee10c5cd1",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315d9f19-61a3-5da0-b9c4-27ba1c777e15",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc48e892-a9f3-5723-8486-b4703ddc9d6d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c6e3359-0469-5e07-a311-60cf5f99fdff",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f481846-0c0e-5212-8a17-498b77f192c7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:652d6e00-2238-5a69-b0b2-a599b5e61e9c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcc87eb-de7b-5937-8d91-6f822b804cce",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@6.1.20-tuxcare.7"
    }
  ]
}