{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5d3cf7b2-ff5f-5a63-8fce-52f0a803fea5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-messaging",
      "version": "6.1.21-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:48a52edd-61e1-5ef0-b6d3-e60dc14fe949",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f0c82bf-f35a-5564-bc31-a62618bd1013",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdc4233a-61b0-5f4d-a2aa-7312efc46d97",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b5259c-b5bb-5e8a-bb7f-549b3028869d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df1acd4b-d436-5a93-a2c2-b28b00a2cab7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cd6d29e-e58a-5eca-8f5c-5d3b213dba11",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20db9b2c-547f-5db7-9c4e-49c88c5ca10b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:512ee0aa-9ad8-58d2-9352-357899b511d2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d24941f-da8d-5c6c-8ca5-f3c736a3499d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1b0818b-1655-50ae-9268-e49e92ff9efb",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bdffd79-ec75-5b88-8b06-498b7b161b7d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af4a6eeb-ad84-504e-8b21-c42135a65c5a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.4 of org.springframework:spring-messaging. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bee169-0670-5e57-9fff-453b8c0b5d45",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a04c3bd-73eb-522d-a5d8-f6e11c53e071",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1fe5453-fb6f-582f-8ce7-eb436c839bd5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88081d2f-d4e3-583f-8a0f-2cfee0df06e2",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5188a0ed-d0f7-53b6-8677-808f41e24dbd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfd70f25-b297-5e29-bd8c-1eeedfe71594",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d457bf-738a-5ac7-a3ff-ad28efbfc559",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:665bcd4a-f310-5a79-b1e0-2adc6e3a3a70",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7b7e2f7-d38d-50e8-b0c6-ebfaea439221",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f5dd696-33ce-5311-a697-78e78a73a7c8",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e728f9-765f-5662-809d-732430082dc2",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed6fc0e2-1edc-540c-88ac-25397cbb9940",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.4 of org.springframework:spring-messaging."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@6.1.21-tuxcare.4"
    }
  ]
}