{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ac2dd1dd-7c38-5095-99bc-9af38fe8bd51",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "6.1.21-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a3860d5f-438a-50c3-82e4-ba89982a2ce2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:466a25a4-8d0c-5808-910f-100bf0ec6d46",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9cbcdec-176d-5908-b5d6-f127f8136e7e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efce2b5b-6777-5ee3-8f4f-9a730f71562a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feee36f7-b776-5003-af7b-c9128e8e8fa7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e8cb628-6f5c-5be5-a350-a3a913c3e197",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6327d66-c34e-5fa9-a282-b612faedd91c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d6c294-0f11-525e-bf7a-44e0ced91381",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71db9c36-640d-5f8d-96bd-0df767480323",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d826068f-02fa-58b4-838f-ed4897710f7d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d70a774b-bde2-5f09-b622-ce43ec9690d7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f8379aa-450a-5776-b06a-8c66c0a9722e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.6 of org.springframework:spring-test. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e160da7-73d3-54ff-8124-9d6527607636",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f8a167-298e-5ec7-92d3-afbffe89dd9e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eeabf08-e8ed-5916-972b-96247fe4924b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1b2b0c-8e98-5d99-8a05-f0f36a694988",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3daf0878-f02f-5d4a-8f96-a2951471f936",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c5d0816-3e06-561d-8552-772a20b3e663",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e02e253-92a2-5a74-8cf3-79e91b97e8ab",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38a4a319-f59a-508f-87c0-86d577003949",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b47bd1d-ee0b-5559-8f2c-bdccc317668d",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c7202f-5d07-5fb9-938e-dfbd4c961b60",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3b47601-7d28-505c-a109-5e608fb2d529",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27707846-90aa-59f4-8c2d-7b11bbbb7c73",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.6 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@6.1.21-tuxcare.6"
    }
  ]
}