{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:164665a5-4da9-5b12-bac9-c2c149f2a20c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "6.1.20-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:914f7bb2-df5e-5ebe-8f0e-a108fbd181c4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53f90820-120f-55da-a87a-85f420ad3507",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2757dd7-651d-5966-afcd-b2dcb14cf418",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8926e5d2-b76c-599e-947d-ff6cf57dc317",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0415137-c70f-5cb6-80dc-3ae58e8fdb55",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff822e2-b68f-587f-b704-166daf77ff10",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c333d98e-6d9e-5863-af5f-bd3228280dcd",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9c7b092-2be5-522f-b696-8b7cec409fd9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ada51fe-0dd2-50b2-a022-dfd683e35ae3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b727228-9e40-5a81-a74e-f2b50d93bbae",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f30807a-b496-5c3f-8cfe-91ec173317d2",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7857e232-aa2c-5bb7-adf7-e0d8729741ce",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44cf84ce-ae38-54e1-89fc-3dfeb8ed2a6f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e76b16ca-9f14-5e79-bf44-db85320b9391",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b410e021-8276-55f1-a259-8a9fac1bb4b8",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:770b0d4f-5aa7-5aec-95ae-d56e70e7792e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea54f65-9ef8-516a-ae20-a75c77a29453",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c904a17-b388-5cd7-a087-c31b5ae55d65",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca7befc-2055-5f3d-a37b-03f26945398b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:739dc22f-4063-5c7d-aaeb-28fc400e2d38",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192829b9-7d9a-51f7-bd1e-ed1594a7528d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bbfd421-ed8e-5331-8559-d43cba862ef1",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a00e63c6-6369-5ec1-8ce0-ed126b072d33",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48c91183-a0b5-540d-9eae-287a4c7a751e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f138985-0675-5269-98e6-b92b46285b43",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.5 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.5"
    }
  ]
}