{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ddcea569-236a-5562-aa04-46ebbb8af12d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-indexer",
      "version": "6.1.21-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:64481dd2-b807-50a2-b591-d1c7731476fd",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ff6158-bb3c-5e7c-a160-5ac9e53f0572",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e948712e-57dd-53c9-9280-a824ef43dc92",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac1beb3d-b284-52d5-9ad5-eb10c2a8706f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aea6aac-04a7-54c4-90f2-289c70350da5",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85af550f-213f-54fb-b22e-942f43e9fb4b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ff8a4e-3030-5346-a020-f6b1b8d7adb5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd18b5af-a00f-50da-a12a-f61c5834723d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01d2880b-4c9c-5639-858c-fd59d0f7304a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af73d3c-ecca-5ac1-9de2-5c6839334a5f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6efbf5a5-b07a-52f6-bc55-ec874a7e3a42",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9290dbac-4f24-51d8-a3be-7d20c316ba1e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a5e4abb-a2e4-5fa9-becc-7daa35fc9fcc",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92076817-57ba-5efa-afe9-f791433459bd",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ed4f760-47d7-56f3-9a8c-57eb7e35b7f0",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75102d5b-68fc-5b65-aa67-2ba581814044",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542823cc-a6b4-5435-8916-68cb086c17a4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da0a42a7-ddf3-505e-a62d-11d1c12aefba",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e610157-8ff9-5fe2-b71f-b13461bcc66a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a70f773c-6080-5928-a741-a49d92615081",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d5fa524-24ee-5f27-a377-901e9e47deb3",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3682453-954a-5ee1-af49-cc9c8615eec3",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f804114d-f739-55e2-8427-e3ad0b435d62",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419b1989-62e4-5240-9884-9a4d54900624",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-context-indexer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-indexer@6.1.21-tuxcare.7"
    }
  ]
}