{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:61ee50e4-84b6-57db-b4f1-7c5015b0e597",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "6.1.20-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ddc4b4ad-02cd-53ba-beba-cdf7d48b02b2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07fc0ff8-d571-5976-854c-776fc9225f42",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf93dc3-38ea-5c34-a870-4c69a2fa1fd3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a717dfd-4764-52ec-acd7-862d308bf62c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:346dbe5a-b3ff-583e-b977-a4395f7b2a5c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ebfb7b-8fc0-5f36-82ea-d52a84887b5b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcda0d54-49e3-5560-a194-ce39da7f6591",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a702b4fb-2e6e-5c49-85c8-da565f9e89fc",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0285b5e-4888-552c-95b9-051dca1f7229",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3e41697-acc7-5248-99c5-118f9c67f728",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:603c8895-2f96-52c1-bac2-3b400d69fd62",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b10db42-6921-5483-a8d2-0c52672567cd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2172b372-b57e-52c8-baf9-3d72e25def20",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.2 of org.springframework:spring-tx. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ec12e2f-2b08-5f5b-9270-dc6c89937344",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c45225f2-188c-5569-9b80-18bf203005a8",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba587b3a-0fe1-5760-bccd-c08e47329cb7",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196a7b3e-7339-5eb0-9a31-ad9417839e71",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1be13572-fbc3-50f8-b613-08d4d4b3582a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33372c87-0aa0-5a65-b9db-ce5f5c47936d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05deb611-f538-51ca-9ef7-e767882ca4f2",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b7561b-7c14-558e-82e7-166eed79f2b4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:010abc36-c304-507c-b7a5-8b94fb37489f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d094bfc-e3ad-526b-94d6-e925a5507318",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8680d906-9b71-5101-a342-041a13b77b9d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88cd8b5a-7d76-5097-9fa7-540f2300692e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.2 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@6.1.20-tuxcare.2"
    }
  ]
}