{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fc613398-3d10-5c6e-8a50-f4715aa28bbe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "6.1.20-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b2abedd6-81e8-5417-9138-3e9602ed0a78",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b9e91f8-dc09-56d9-b867-1208bddf8f5c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a606d0fd-0a4b-5500-85f2-3d116bfb4f93",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f74202e5-0ef2-5d43-b8e3-1b15e49cdbbe",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e47abb14-4589-5312-a863-7cc9b3882f3f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b991b67-4153-5afa-939b-1aa49578f003",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c83b409b-c5db-5c30-8b7d-6f97bac96faa",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:191a0015-df26-5356-92cc-834d540c1c72",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3e78ef-3c0c-583d-9d19-7a6202649b0c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ae7174b-3e4d-5638-aa7b-c48d05942632",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c34eecd-d807-5fa2-b942-b3d5774cb2a9",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2d3dcb5-521d-5905-8709-3aa6807483ce",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c91b92b0-c975-55c7-a15a-88ed35d6ddf2",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a69e5e2-359b-59a1-90a3-33436a1f0b10",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5d02c3d-d939-5c98-b964-f385688f33c2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:861a02e7-1f67-582a-a975-7f0ddc342dc5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a01715-fed5-543d-9d80-e6c8ddfae39e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3419579b-a4ec-5094-8d6c-a45fd13cff60",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ce557df-3438-5b2e-8868-8554a0f90db8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58a32022-7747-5d03-a118-ab3cec26f08a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22f58d1e-e04a-5035-b9d1-3c896b865b8e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df205c39-f893-5c0c-8e0b-e49da0d41268",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39001af5-74d1-5f57-9a2c-657cf73eca47",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06757181-ccc8-5c8e-a3ce-fda1eda45d4e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c43e0d8-d8b7-56d5-9f2f-7641cc30364e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.4 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.4"
    }
  ]
}