{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bdd28570-8c78-554e-87d7-7c3a3225c4e6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "6.1.21-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b84b2edd-4eb7-56a4-80bd-864533ae434d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38e46640-9ffa-5cfe-a698-dd868e384b8e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff7e799-14a3-5a71-b949-751038d81f5f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:689a0d13-d0f3-5e4f-b1ad-9897cdfc4dfd",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61123137-425c-5e40-9e7a-4e0500c840d9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b8ec125-5605-50d9-b733-0f7505deaf53",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f55f112-cf3e-552f-b396-0b456cefb0ce",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2a5911d-73b7-53be-9191-0461bf2a8232",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce222ad8-97f8-557e-9973-03bc374998db",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcc509f3-6761-5510-b8d6-5386838fab42",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca6ed9e1-8423-57af-b7f0-0f76a2ef8905",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c6f4a13-149a-5b0b-ac31-29961f5063ee",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.6 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4354e3a2-0d37-5bea-9b3e-289ca7b5b12e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81d61fba-5c24-5aaa-b43b-20dbafde76ad",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3a4f41-5f6b-57df-aab7-181a1826441f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a449d3bd-7f5d-5b4c-b019-315506ac9f4a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffaa88e-9e7c-5947-a705-5d7f43b9fe90",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1b917f5-0d2e-5313-92d7-2394613973ab",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30126b1a-1df5-5694-82dd-03087824bec6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9240d8-e671-5481-93ce-70be6fbdee17",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce789ebe-122a-5716-a962-d8d84f945fa3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5093185-5944-5145-b1f5-30aafff2370b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9281e8b4-3323-5edd-9103-3a255a76d2de",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2412a4-1c07-5f8f-a01f-aa5340f31906",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@6.1.21-tuxcare.6"
    }
  ]
}