{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:705c0a5d-1cc6-564b-baf7-8156b29a2cdc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "6.1.21-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d835328c-f602-536f-8dc5-7e5b3a0c0ec4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1cba640-4883-5fe1-a18a-fc3471959fc2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dd2cb70-9928-5764-980e-50cf01e1288f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adfb6779-6dea-5280-899b-f680b9a50fd5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e0c2cb9-871d-565b-881d-f81a8024d9fc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e450187a-b3c8-581e-9c19-b05ad8c83f62",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87d54097-3068-5fd5-b93b-075fe4132ea4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcd7e292-d172-5d7a-b9d2-53b223882c2b",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54ba25d8-ab52-555e-b2d3-48d6ef6c95af",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:398eb7b8-55c4-5f2c-b6c9-767dec8c245e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0834711-dc51-5544-b1cb-1ec50b541f2f",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97a38e01-4c7d-5794-acbb-f22853cac6de",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d119fc70-56e7-5d05-b3ef-ca78203fb668",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d21cbe9f-f411-5e61-857c-e88d93d82db6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b8bf758-976c-5022-af43-79bd0ed0ec49",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c904cf62-ee73-535f-b3fa-50488da759b5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29aaeab1-0192-52f8-89a3-37ac584a9375",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc90d5f6-f26b-5eeb-b5de-42c1be39d7ee",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d062fe-0663-55a9-a62f-8b8f2e1ad704",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc11a164-789a-5406-afc1-25dbce4964c4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cce0c81d-6d89-5ec1-b9b6-8642bf920528",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae3e954c-8c69-5358-a959-53198543ee3c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435a3ec5-818a-55d0-b8de-22ca2f96565c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a20d97b-d045-5e9b-9e72-83aceacce8d9",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.4 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.21-tuxcare.4"
    }
  ]
}