{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a94826a9-7d1c-5d22-807f-4e91224c4d8f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "6.1.21-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bd1a79d0-630d-5a3d-b86c-edca699acb14",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51eb984d-113c-5cf5-b3f8-e7b5b6761ff5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81d38913-1615-5743-a7ba-49fa0a8cdeac",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f5d999a-a2d3-52eb-b2d5-90c1cfee7c4f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb356e0-addf-51b8-9674-894e13967963",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cf6e28-0ec0-55d3-9382-f0d79e09c641",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7374b065-3562-5296-b56e-f91842baf2d1",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c82bb06-aa1b-5e3c-b022-7c2eb7cdad6d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:898caf0e-42e1-5bad-be26-5943cfe75b7a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b1ee16d-406c-5d20-9fc2-5ea2cb11d261",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef680038-e9e5-5b42-8814-687054b3231e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9cc98c-170b-5aa0-9e18-e17209ea81ab",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.6 of org.springframework:spring-tx. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55f05b5-f2ce-5176-8370-e757e5fd26a3",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e764de9d-40a6-5fe6-8d37-42aa297786a1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eebda53-8222-59ab-b0e9-59a26738c326",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be0793b4-6692-5c53-9a3e-8b841bab158e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07eb9507-7a00-5d41-b6fa-fa51a4984759",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bec139e-c4e8-5d5f-b06e-304e4c9aaee9",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a80921-383a-5437-8dbb-8302416b308e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a80d165-b50f-5d7d-90ee-073964823489",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c49411-5a62-5c73-9e4b-cb5c2d5547c5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baf89fbc-9d61-5f01-9ab5-41685177ee16",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdab6597-2f5e-57fd-a104-b21547fdadd2",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73e25f2f-25b3-575b-9e17-1c82cb81c2e7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@6.1.21-tuxcare.6"
    }
  ]
}