{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:df09af51-f7b8-543f-827e-0198c4b11e1a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13",
      "version": "6.1.21-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:4886f174-1e0f-5361-9453-7afa278c3e2e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:08d10342-19df-5333-98f5-7b5f84cb301e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:edd718e1-17f7-5c37-be1e-412cc24d3a3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0dae8654-2bdc-572b-a209-b071f249605b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:01721fdf-9c64-5b0f-aaef-57a362c2a1fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:8f86a577-0351-59ec-873f-7f6ad5280d13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:44296585-cff8-5b95-8997-7cb832639db7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:4a9f282a-1987-5ccf-989d-78ba49e803d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:74556231-4789-50f1-add9-9f55649fec84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:287915a9-699d-548d-901b-d63e91387cb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ee0d2a65-1954-5efa-a3e8-1f8611d831f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:45557894-d065-51ca-a7b9-8d9c8ff0e8bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9898424d-1c73-59af-af72-1691ee5b2ed3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:cfd16868-9242-592e-b06f-8686b4c29b7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:73ff894b-4515-5f40-acf6-dfe55ec67d8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f5604728-9534-5b70-916d-c5b72cfd94ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:651442ba-f937-55e0-aa9d-cf9d6a99915c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:928a8155-922d-50b9-8744-9d6d5bbbad2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ac753861-9ca0-513d-a6d4-3caf13a6cbec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1394c8fe-ac6f-5e68-8d9f-19f22bc67943",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:496e0891-4085-52c9-addf-fcf156c275d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c3118f2e-c5d6-5233-a567-7bab8fe788d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:60c65258-b917-56bd-9a04-6b1bbcefd823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9084e87c-3b41-5904-ada2-269b87d5e36e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:6910229e-b6c3-560f-a8bb-51bb13c11f9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9c7ea86e-973c-5aa2-81f4-8522c54df4fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47885",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5b5f8260-04f7-524d-84bb-c08a3da2b2db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ca905593-6a30-57cd-9645-258a9a810d61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f1dacc81-9346-509a-9533-b4b1f8d20bb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e2427f06-bb5e-5caa-8120-a3fe41dcfb89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f59c01b3-1c30-5025-8ea0-a6b8693a3a15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d30a5111-213f-5979-8512-4c0c361c874e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ba5f5b8d-54d0-5798-a1f1-c91aa8a7caec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ed99bf8e-776a-5cb6-a359-6c940a81351a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5d4e2e72-ec6f-5c33-97b3-16caa915407b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3a955b2f-60ee-5a7a-813a-380eb2b0e473",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e39a69a1-4bfc-5185-8d39-0a9115e7625f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d25ca447-bb56-53a6-976b-4521dd4d42ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d5a4f7d3-6c01-5250-a3be-59363ee25994",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.1.21-tuxcare.13 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.13"
    }
  ]
}