{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dec9e994-6e7b-5423-9cf4-cc8ad20c217a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "6.1.20-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ee2b6e1d-e56d-5b41-b774-aa15441a025d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea481b68-83fd-50ff-bd1c-bd83ce390feb",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91935d0b-4d95-5804-89fc-da344b2e377b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870337d6-9821-5d34-add1-7e8a42399e4a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8841735f-10ec-5149-8c52-be6ece55399b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd94d771-a839-5a4f-996d-76daa83e2ebd",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3ce3bcd-20e5-5fcc-9840-4fdda51c0379",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:882ea838-9ed1-5c96-a10e-61bdcca1b66f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c726f2-5f0a-5264-bbe3-3bc0047e875a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90559538-a07d-5bf0-936a-121818aca976",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaad6cba-a406-57a1-9ea0-29cbff91f518",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c12dff5-28db-54cd-bd69-bb34d544d49a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d9f8ce-3306-5a1c-9115-1bad9e806d22",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.5 of org.springframework:spring-jcl. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24888a58-2af9-5804-a744-740fd9fe9522",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fef45a23-d666-59bf-a9f0-c6daff191b09",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d829226-5217-559e-a84a-210fccf8db3e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:013c7911-bf85-5de5-ac8c-a8c201642db1",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1f9229-df6c-5755-8f6a-84f345b057b0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fb48d9-2024-5956-bd51-0844ad03f33a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb8fdf1-e169-57c4-a6ac-f01de210c220",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54499504-23fb-52c2-9888-005c4c9e39cd",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c95541-f5d1-5a05-93c7-0a6cd9b98bcd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a9afe4-3808-59cc-b0db-ee7299428441",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f6c9c01-3622-5c1f-97c2-e9a1eb70058d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d440d0a4-26a8-57ea-89b2-e7e978f9c316",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.5 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@6.1.20-tuxcare.5"
    }
  ]
}