{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:50b3c238-6b43-58e9-a6f6-7871bc6b5d4f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "6.1.20-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6ffb3bc5-d193-5438-9f37-b86a75b36d35",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-orm. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6e5d592-2c26-55b7-a484-bf8d3184f088",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b6ba853-68f6-5774-9d8f-53ec3f7b0e38",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f9c20e6-ef77-5643-9f2b-7ad27b23c395",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1f0059b-aa3e-536d-89ee-b1fd682883bd",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc1b26b5-355a-533c-97ba-45d4db0390b8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88792da8-cde4-59f7-9bf8-c2cd0f8fa9f0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a584d52-772f-5259-b978-bb4cb6f25a0e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae0722d6-063d-587f-b70c-590924f218e7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c2a7036-96cf-5442-999a-54b2a9185766",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8953bb10-119d-596a-854e-7a6a975b60a6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253fd3d7-f19e-5bf8-a020-2308925a6044",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a507443b-397a-56f3-996d-7aaad6520a8b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-orm. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cf1d90c-ca06-57a1-b0e7-467fa7c926af",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f2ab129-2ff5-547e-8c45-e36405b23e1c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e360064d-c4a5-54e9-8d82-67bf1dc12a6a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb6270a0-3922-50bd-9a01-965999f74b00",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52610ae3-c4b3-5a58-931e-2571d10fe58d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf000e1-4ff8-5914-a187-31f2165e6a49",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee5bb7f9-4cd6-53fd-b04a-f6df2cad830e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14d0c594-9d0f-5adc-9b95-8c8a60b3160f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:453109c3-24be-5bca-a45a-f98a6925ab2c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b889f11-e426-56c2-9bb5-db523d6a2e43",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eda1da6-fca0-5ab5-8c96-cf0d9488cc07",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1efecffe-cbad-56a3-8561-c50aa63aca69",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.7"
    }
  ]
}