{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e56370c3-4d90-5234-899f-4289a9ee6edb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "6.1.20-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:eed63521-836e-59c2-8167-b8a92abecd1e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5674daf3-f485-516e-8d6c-2aa48ccbdc45",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa8dd91e-0a2c-571e-8b47-c60777ca2df8",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efee1c4e-4c5a-53e9-bb6d-656b6b2a70d5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:558e853b-e01f-587a-a1f1-66f090b59065",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b578670f-98c6-5b4c-8f7a-cd74367bb3d5",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4fe30b-3dbc-58ba-9551-d800aec94741",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5501d59-f593-5740-9170-95191c7c57c3",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6df459ea-ffdc-5131-ac87-dea982cceeec",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8511b18-86b5-5fce-9d69-34ffacc9a84a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8647e820-ddca-5dad-8c60-42c1291dd5b4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ef69a83-4092-5d36-83f9-2062662879ac",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1e2bd9f-6077-5fe4-814f-cae97a2caf58",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.3 of org.springframework:spring-test. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa17aedc-a034-59b2-a54a-682b8a017586",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edbf01d5-999d-5d83-b5c7-0972faba8849",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7de90b3d-c23b-591e-8c00-529cedd23333",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64346e07-27f6-590a-b033-b9624368fd4c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2e92a47-7056-5376-b149-3b27a67fb754",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b68b77d4-5f3c-5e2f-bcff-8c9c44954d7f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ce61eb-415d-5122-a1ac-a7ea32e9c1f5",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33024582-8ec5-5841-88a1-5d3cc163cfb9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db64b451-c9c6-50cf-b333-037980a01b97",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be77361-85d0-5640-9bc4-4e55c55bd88e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c24797d-04b8-505b-bf03-af24283f7395",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c13a64c-17d8-565c-9da3-4740f27c9a53",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.3 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@6.1.20-tuxcare.3"
    }
  ]
}