{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fd57ad16-1ac7-5b42-ac5a-9ccd894afdb8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "6.1.20-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e8ef6b68-7d6f-5367-88db-334f2df1db4e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4584e479-7f02-5add-bc78-7f93b6303140",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5982147e-3dcd-5009-a1eb-545522acaeec",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aa409ea-7b71-5e5f-9b84-da7d8fd0a448",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32f9f09d-c9a8-5559-948f-e5a77f67e0bb",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:437936f2-75f7-5adc-a6d8-a02d11b471a2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0965053a-f937-5676-b264-ad8912ddfde8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771c52ef-5b71-5906-8ba3-55d7e2ba9a30",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4da1d01-36e2-5588-bbb4-23b9fdfb367a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:861432c8-0cc7-5f5d-8e49-932410ece57c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fd05428-1df5-5e60-a3f5-be217458d0ed",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a557f02f-864a-5a78-a531-5b1ee720c16c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45296db1-b6a0-5d2a-a641-a846c7ac95e9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916632e1-50d1-502c-8184-d389b06b3b58",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc139af6-6c59-5535-9c68-755472539f02",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b167ad2-9933-5c94-b3dd-17b9e3c3f569",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bed03e0-8632-5a1b-a6b5-cbc8a71cc163",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3450c99-c3ca-50ef-99ee-8b51261c73fc",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acd42907-589a-52c5-971b-ffc528a7c2b5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f75dbfa-82c8-52b9-816f-170d1e687ecb",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7ae45da-305b-588e-a681-a58025778f7d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47a31e34-efdb-562c-8bbe-d418b3406486",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6119cec5-2742-5da0-932a-e04b1394c33a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0991713-634f-5af9-88cf-d901e9473336",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c44c483-e53a-5db6-9f14-7cc074cec143",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.6 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.6"
    }
  ]
}