{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5e503ebb-3aa1-50eb-a589-20f320dc97d5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "6.1.21-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4cc3d314-38d7-5257-93f1-09899613cb2d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3309a839-be57-5ebf-a988-53a034250965",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46d53b31-5ea1-55f2-88bf-65a74bdb14c3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a154a8eb-f37e-589d-8155-e4e5c0aca006",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84a1a83d-194f-566c-8318-f68d35ff82e3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dac8d521-77b5-5e5a-b17b-f83634659703",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03f6f122-cb2b-5989-995d-81a8a1d3857c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66785ae6-3aa7-5469-80c1-475d6d3a19c3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d93f85d-3fd1-5834-8933-b019ea6e74c7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:589425cd-dae1-5e3c-9d5a-9b9f6df98ba8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec18860c-8d9e-5b0f-b45b-d15660ec534c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:412d7a2b-c3e9-5198-a53c-e1724344fd4d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.4 of org.springframework:spring-test. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b586bb95-81be-599d-9a39-5ae814666aa8",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e63b7db0-1481-5483-9233-2946b23c8ff5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b9a7c1-c428-5354-8700-6eba4960d516",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c924563-7a96-5f28-89d5-3420b9ad509e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a76bf262-75ea-5799-9e37-54dea518ce46",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea216c92-c410-5957-ab90-ffd633223be8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0440d66-86d2-5fe1-84b5-d581afec1f64",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1afec162-0bf0-565b-b35e-5205f62a7c14",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411ee434-aa5e-5d27-99f6-841506706489",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca9e16d2-0b7b-5200-991b-63464e2c4b6f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65422ecc-6303-5692-a742-689576cf6fba",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa80651-acff-55c8-95db-5a9b797884c2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.4 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.4"
    }
  ]
}