{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0601f048-deba-56b7-8627-74a2a08e85c8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "6.1.20-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:97db78eb-2157-50d9-92db-693c8380053e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df7383ae-4414-5d57-9e33-de8f5cb73dde",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2276a84d-57c6-51ac-b95a-3a793c4dd2f6",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a08c2ea-c721-54d0-a7f7-427daca072aa",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b738c4f2-2b57-5876-87a7-581ff61aa4ff",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9bc5f04-b61e-5a56-8136-63b2d36e31fe",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48808ea-6b3a-54d7-94b8-d0828079f852",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d451edcd-3356-5bc7-8bde-7eaf8f688636",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177fc0e4-c482-578c-aec6-301ea93ba53b",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ddd285-31e5-5aa2-9564-8deb6e8831b0",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df743f73-f475-5398-a5bf-60e9560337a6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f228a70-0c9c-55f4-a926-6df6e0f90b2d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a0adff7-2e03-569d-838b-e122239e185a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ce1a6a7-0a86-59ee-ad2c-b6c13b120f46",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d010db0-a93d-521b-abbc-ce25c9c375eb",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c92bbf2-5ab4-52bb-baa7-10fee473e6df",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de8d6074-c060-5fc3-9039-9dc61a977de9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:888cdbd5-b816-5de8-b46d-3d87c7d3d721",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f7b46d-bbc0-5079-a24e-e8b0291d1d7b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85af41eb-f445-5003-80ca-7e0070665c40",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f07ee00-3f8c-51c8-b439-2691f5ad126a",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7728b77-6b9e-5d86-b57a-d976db2f85b3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58799827-8910-54ca-8fc0-e257e04193ec",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:506bbad3-8dde-5143-8ff8-a557b299f7b4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2271ee83-209f-53f5-b707-b9dc2948f419",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.20-tuxcare.5"
    }
  ]
}