{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:30ab4c63-560e-5212-a5f2-6d5fd5197325",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-context-support",
      "version": "6.1.20-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7a02a2a3-93c2-5637-b200-e1b560d1c80f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef5c9d2-a592-50d5-877a-98b32eff6903",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53acd101-ca19-583a-a962-a7dc7ffe26c4",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23337a6b-de70-5d6f-b6a6-19ec22324772",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fabb101-0586-54a6-b95b-8e26a5a0922c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b075bd2-deb8-5690-9256-b89171312405",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc871936-5732-579d-a59f-2ea45149f689",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fb8ea47-4d71-53a7-968f-cde416f02c16",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88bafbc8-dc39-548c-bf37-0db7d0b729df",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b466d4-5d2a-54f2-8e71-2efbeb3f6e6b",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ce4a14-1d8d-54a4-b138-e1def3a93815",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:571b9f10-f13e-5edd-a1c2-dc194fa62f2e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43f4edce-af97-57ce-9845-df1da81f28df",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.5 of org.springframework:spring-context-support. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d25160-7cc5-5e20-909b-9cce4b4ff9a0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f4b5ce-0617-5be3-aa9b-cc34a215e55f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd62112-b785-55f9-b1e5-c4f9dcada22a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3919abf-b736-5458-95e9-149267634af3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97d75a34-8a38-5f07-bb54-8d0c71556d8e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3bff40c-bc6b-55ff-a294-8aeda5c16fba",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10248918-0c5c-5ae5-bdf2-d75fd823f898",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df3e894d-d3b8-5e0e-9daa-34b2a4e1419b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38741a4a-84db-5e19-8383-e84fb21c773b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da914323-98db-5030-99f1-ede3acb7ff2b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:079c72b5-0da3-5a0f-bdb7-f229b6107280",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48734923-a48c-5149-97d8-7ebdda5f3983",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.5 of org.springframework:spring-context-support."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@6.1.20-tuxcare.5"
    }
  ]
}