{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a0df62fc-1032-594d-90d5-ebbcb1b5abe7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "6.1.21-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:da989b55-2803-57bd-be7c-385bf6a8ceae",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:101a5b1e-a36d-5e03-a67b-736f69fc78f2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9e5ec62-4e0c-5003-a35a-257b13e54623",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ff7290-7617-5b47-bdcb-1c731aa65e13",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f51c323-0c7c-5f01-b986-14de3b1426be",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b7edf7-89b4-5d06-8516-b6ea9ff7fa04",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad566b84-3d89-5ce9-a4b9-5a2148b55030",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411af87b-3fce-594c-9cdb-5caabd635eba",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7652b338-cb0f-55c5-b68c-4489099f8e47",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ec0529-22fa-59b9-8e20-a20092703c2c",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf28049-09eb-5559-b361-3ee7b3ba6b51",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2803190-51c0-5136-ab54-3f5608bd5a9c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.5 of org.springframework:spring-oxm. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d94da983-bff7-5b1f-a1d4-bd56ed3e243e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72b7738b-8bac-5b37-ba6d-ed7f594c07f2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cd72548-ee3d-549b-bb23-333b5d7393c5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66fef5a9-5690-5d48-8821-a5ddb4ecdd3f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8625a4b-9b26-5a41-9444-e655f246ac55",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8e78d2c-1732-5fd6-b49f-f61991372663",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adce569d-5c9f-59cf-a9dd-c7ace138e6f9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb70c771-d4a6-56cd-b4e3-b81b3ecb1e6b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd7f847d-d553-535d-923b-6e1affb6ed81",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcbb1ac-4dc1-51c4-8daf-a978568a1626",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c9d205f-914d-556f-aef5-3f71bc1bae1a",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f764829e-0cc6-529b-a1ff-2cee1b2320c4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.5 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@6.1.21-tuxcare.5"
    }
  ]
}