{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1d9dbc39-d90d-5766-a87e-cec2456d7aa5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "6.1.21-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f2dfb4b7-1727-509f-8213-c805af9dab31",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a354ba7d-0568-51db-a11e-2c72ac301bea",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c6b081-f3f1-5386-ad39-53ca92b3962c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77b834e6-3180-5c24-995b-fbff4728d905",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:969f08f2-18a7-503a-b753-b80cf245981b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:268dfa4f-4b2c-54f3-a1d2-86172b9f6a81",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6de2d2f-6f89-54d9-8ab7-d27961b3843e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4b31a1e-39c4-5999-ab94-6f09f88d39d0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88f1c422-b96a-5856-acd1-3e34392940b2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03420861-b2d4-53f5-b02e-15ad420af226",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d4af957-38af-5f1d-8bca-6e31e70bc41c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06110cf-af01-503a-99cb-67b1ec6fd2f1",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.1 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb85d219-da8c-5a39-9473-85f7b10ecbca",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b04f4b5-e613-541a-ac0b-489c3834a400",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e9e7ab-1356-5195-927e-c1ea6e621c00",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad2937ba-e676-5a94-96bc-c6956f61549a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3315962-e6a4-591d-b1dc-35e704f7b0ea",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cebb67c-063d-5b7f-a1f8-88f646bf1e26",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:485c446d-3609-51de-ad0e-eea8aa1da4d0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73983f49-9a9c-5280-9cf5-cae718bf0a42",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5b4c15a-66ba-5d8e-8daf-e7c9b8e3c0d3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b19a457-2e7c-5929-9b10-bc316b851dd2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79430dfb-fd98-5b48-81a5-c4fed704aece",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb385b97-0725-5b5e-9670-e99a353d4ba8",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.1 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.1"
    }
  ]
}