{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:350e9a1a-cba7-5073-9aaa-621a1d0ec125",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "6.1.20-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:972f5c3b-1f5b-55ae-aead-203277aadcf9",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b8f4f59-60aa-5894-b630-d53434bdeb4c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a044ba-bbf1-54eb-bc2f-33740f5dae0b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e88123fa-0d5e-5845-80eb-2b3ea703c5b8",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a47bf202-86a1-5b08-a4f4-cb3cf9267fa5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c39868-3a64-59cc-81f6-91af0914812b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ca4ff0-13f2-5402-a2bc-a9358e0f5e70",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:069a0cb0-a370-5479-83a4-194eb956475b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c270303e-50d0-5097-9ff2-692bf445f28f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b6a6d5-7cf7-5d8d-873c-107fdec7d382",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f63568d-d858-5bf7-b6c6-e12ddb07a38f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e3bdfe-f940-5e10-aa7e-c48551bfc1df",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:598f6b6c-4fca-5904-83a3-e0c41e3f2587",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56683980-8022-5ccb-8528-f12469a14246",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01eb1da8-0259-5f73-bbfd-e4c2a9c303e3",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae4b9fbc-a6a9-5fc2-bf00-b890bf54674d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c0e66f9-8593-5a2a-9ea1-616f7a8a0996",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5333bde9-8a62-5933-897c-06f354741c57",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d29a13d-d269-5383-9a69-4fe03300def1",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7cd8998-01ef-582e-a84f-2bdea6c45ae8",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f572da7-bcaa-5bf6-bd01-fff7bb484bd4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85ed16a9-f74e-501e-83a4-91b776e7d10e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed67dd5-984c-5a1f-86f0-c0c24482cc51",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce22c7aa-81ac-536b-9b7c-ec223e8778b4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc307779-ad7a-58c3-9244-784704fe60d1",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.7"
    }
  ]
}