{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:09a2efb4-37e4-5b37-a69f-a1b7910a61dd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "6.1.21-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:90d8c76d-1091-5da0-80b7-afedabe256b0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e4aa7e4-6c7f-5ff0-af0a-2c56c22ae0c7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4815147e-b8a4-5a24-b9fe-6d48f96a3a89",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86f9a8d-7473-5364-8b84-35eb38641d3b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f49f53a-e4aa-575a-9047-54db50ba1643",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f595f2-e958-5c0f-a05e-4ce1394be009",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9da18c05-9026-5ac2-a305-05a1789b5460",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f6a217f-2242-5eef-955a-74883fee8ad1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:346e6f31-674d-5580-b18e-51fe3aaa7b8f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12af0b8a-86f5-548e-bc47-3da99f71680b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55b85feb-dbf3-5381-ba70-de8cfec2ff5b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e529fdac-05d0-589e-a207-7d97757d07bf",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.3 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e50f94d-f683-5e8f-a39d-0b307994e4f0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:284abc9e-ee5d-501e-9307-e1c00ffbb6b2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a4efd89-917f-56dc-b8da-f1a7293c051b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf9ea9f-8919-5a7b-94e9-1b45822cc04f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e23550-2ba0-5465-afe4-032a6387fded",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d89d80d5-5ca6-5cb0-8788-7455544b97cc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f371bf89-e817-5869-9ee4-2f680b2e5ef5",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a71b3d8f-6c8a-530f-ab82-086907829b0b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:993d0fcb-6596-521e-85f2-196588db79d2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd990896-4cbd-56f4-97a6-cb6460203626",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77c5a2c9-2a04-5ba1-b279-215f97f7d9c3",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89bb5eae-3616-50be-9466-ea371cb4f68b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.3 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.3"
    }
  ]
}