{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:97fef12e-f154-59e9-a29e-a566493b1822",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "6.1.21-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b14fa2af-85d5-5961-bfac-0ca01b5e7cce",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b976447d-f823-547e-b2c7-17d998c3fea9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9fe62ab-a02a-5016-a0e0-97023732a9b3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8422664e-d202-5c9a-bb63-2b132f8f30b3",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59075450-ccc9-50ad-ad83-be89507bf384",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:490c77e5-8c5c-54eb-bdd8-eba792c65320",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d0b6b1-dc52-541e-bf2e-207de1ecfb6e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84aa066b-fa7f-5a63-a886-b7962a6d1df7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ac0978a-5ce7-5221-9840-6f93e78350b2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aff34e2-162f-56a4-bfd8-a1498b20c301",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2010c39-e96d-5f17-89c3-e877df8677cf",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e8326c2-aedb-5a6b-b587-1ed567fa1aba",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.7 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27a53af4-b8ed-5fed-b12a-9c0e435196e0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5adc1116-f78a-5ff6-94ce-2f3764bb797e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1139db3-209e-549f-8fde-d80962ff4e2d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe634171-3b4b-50f2-977f-f18e38c24383",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92dd7838-b007-5e21-97b9-261e637a1f23",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2bd1975-26fa-560c-bc47-e672fb2136c8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69d501da-66ac-5a60-9106-1cfff742a3f6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257359a8-136f-5c7b-a132-f25923d7f994",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c217221a-edb0-5fa1-9788-bb1b20bcb1fc",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:878c9ed3-99a7-5aac-897a-5c3283882b4b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4730b063-63f6-5896-a57a-e14a49d7bbcd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:740ed685-e07a-50f6-ab94-10f29eb7d597",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@6.1.21-tuxcare.7"
    }
  ]
}