{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9240c087-68ee-5dad-8f6c-ca06e37df7d4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "6.1.21-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6971b947-bcef-55ec-9dd2-ea35142443d0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d44ad5a9-91f0-50d2-950f-be0460b0c768",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285f7c24-6d3a-51aa-acc7-2be2cbe7c498",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fe1f0fe-c50a-5cd7-a107-82d88ac02b88",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9178395d-6748-5490-99b4-6d8a72a59498",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d849b444-00a9-545a-89a3-5e1de9da08ff",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:392aaddd-10ad-549c-afd6-345d35f1f7a2",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c1eb18a-e50d-5895-b5f0-49f4ca607c70",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5231393-c8b9-5a63-9c68-d363e6646c5c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce970378-2473-505d-8526-ece7f517e1d6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ecaeac2-f636-53e3-9bd2-8f3c3fe2d696",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:638738cc-4fef-5184-b37c-e46b5477754a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.5 of org.springframework:spring-test. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc30abff-c09d-5905-8a23-e21218e879d5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15574cf-8088-58c8-b363-0845b50c5513",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56029d5f-2cd8-52df-a5b5-24b2c9db2222",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:889a92e5-5c85-5ba0-93c5-82a894083129",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:517528a4-69f1-5fac-97d4-0fb433b2237f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:280e69b6-66fa-55dc-a4f0-785840c62ef8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e62e433b-06fa-5a2f-9e89-683349e467d9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59a31e7e-b3de-5541-b2a7-9cadc3876b5e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89594e9b-4614-50c4-a875-e464544bc8bc",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a5d9003-7e84-5729-931d-f4440ae1f0ac",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:784b4c66-7c77-5774-8466-0acac684547d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd557810-0db6-595c-819e-77344d94217c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.5"
    }
  ]
}