{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:477a116d-f2cd-56ab-a848-d53c1801b768",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "6.1.21-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:74b24192-8a32-5e93-a5f8-e9ea17760748",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24cddc57-b4f8-56ce-a3f3-35247eb4a571",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47423fa0-736b-5d7a-b943-eef03deacd8e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096d3cb8-7e7a-59bd-b433-e138b57bd6e5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec33e15-b242-54b4-bbf5-16e30895c875",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38fc5cbf-3b90-513b-a149-006f21116918",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca5bc669-20d0-519e-9530-139c0bd7b916",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f94bed2-bc86-5495-9f7e-b4117dfc7065",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:707879a9-65aa-5d80-aa49-04dec2b876b2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c88dbd-9e3a-5f7b-9d52-c9c55a3cabd7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7da6cd42-f0d6-50c4-af60-3684ba1c96f7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:908b3d02-f3d3-52d3-8db0-7c7274a3bf3d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.3 of org.springframework:spring-expression. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:148640f2-4948-5af5-9765-7af34b801b12",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca5a00a1-836a-5374-818b-62a0298fc70e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4843fd3-d2ad-5840-8709-c159c6cad893",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96e597c5-bcbc-58c8-b65d-fc8da7b6c228",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:695ded38-bdf8-5058-90a7-30c0411c6408",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e554a1-58f4-51fc-bf34-8cd9a25aeb49",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37e61173-aad1-5a9d-a4c2-9419f2421ef6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c93bcebb-c9d1-57d4-910d-0894e27cae48",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11bae963-ee51-5744-b079-49620e2940a5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa98f0ff-7c2a-5448-b426-faa4554d5c32",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae8e3055-32eb-5e07-b7d0-f03fd7bedaa1",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737f39ed-7ec2-5159-87b4-f29d4a77240b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@6.1.21-tuxcare.3"
    }
  ]
}