{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3bf89824-46d3-5b70-8d5f-ba7675f6d1eb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-core",
      "version": "6.1.20-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ef06e920-c91a-57e0-bfce-2cf276f2f65c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29a7e1a-8145-59c9-81c8-dfb54765d282",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:413595b9-351f-511e-8c05-7eefc2c60ad2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14c3cf2f-e918-5b85-87fe-c675555a3b73",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e36cdb97-948a-576b-9bbb-325ed0d477ec",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e1cc9de-8982-5a87-aa3d-a1cdceb24c10",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5197820-fa48-5aea-869c-6abf1a2f2057",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12657798-9f35-5a9c-95ea-a41b0a95a8a3",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ccace68-e578-5d39-81f1-4914b70485aa",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b9ce6b2-6439-5761-9554-4f699d3f9753",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94489878-61c0-528c-9595-4576c16ea4e9",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6af978a6-6192-57ec-a00a-8e3054534239",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb4d5dc-dd06-54c6-950f-a635f74b3edf",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.3 of org.springframework:spring-core. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e6d06bb-d5b2-5d94-993c-9a63051e9e9a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b35a3c-f820-58a6-bfa1-5bfee8f22731",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc28335d-c1c6-59c0-89f8-86886e4efa05",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8c21103-e239-596a-ae0a-d70785b0275f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1adf56e8-bd98-5ff5-b65a-fdbcc44e8755",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a91bbf-bae1-5e9e-9eb4-b76b467a9fd3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b0be17b-8fee-5702-a6a7-e548df59b150",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4324579a-c80b-5983-af06-b739ece24d59",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d801d66d-9561-54cd-af5a-c364f1cb3937",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f64bf8c7-8dde-55ca-9a67-c54071833a3e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04bd8c56-1c0c-5891-be8b-4dd9e228995b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72d3c872-fab0-576f-add1-6e3914248b46",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.3 of org.springframework:spring-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@6.1.20-tuxcare.3"
    }
  ]
}