{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2ab86f08-909e-527f-bfbb-03a98f9bd3e4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "6.1.20-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:57d6fc13-04c3-5420-81c3-628823bed530",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15362833-ddfa-58f1-9d6f-59d63af97fe2",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af5ba2f7-c85e-539a-aaee-d496c8899b2f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba392a8-5ca2-50ed-a1b8-021d0b7b72cc",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c394aaaa-b9e1-543e-9f07-264975556398",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27a5f744-9c40-519e-903c-45a78f9e9f62",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70c81009-518f-5e86-a482-683d33bedff0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f25d512-9a4c-5d79-8c07-8e1c89699c14",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eecd65fb-fe54-5144-b77f-8c9c3a00c3bd",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d42d14c-22e6-5a82-8a87-05ec896c053e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28be0084-6821-5ee0-83e7-bb7b6c5d0f4d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2d9b13b-d351-5759-8253-b630a4cea585",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59ca7297-e671-5c6e-8d96-5c7306a3f9d9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.5 of org.springframework:spring-orm. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f7e5b9-b65c-5594-a47c-666984a4d7ba",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5dcda7b-fe72-5d8a-ba32-73f9b105c872",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e14be8e-811b-5f5d-89ab-820d7e6cdd9c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87d2b6ef-8b97-5536-905f-cbc95b094a28",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1b97b20-ece4-57c1-ab84-deb3ee271e03",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff066fe7-04a7-52b9-84b5-46ace303f739",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8b68426-d19a-5eed-b9b5-4f0e8f0e3cd1",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c46816a5-5347-555e-8cfc-ab370850483e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b49917-1145-5cb3-8778-a261ad236db0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bca0bd3e-a836-57c3-8295-daf7fb266c04",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c5143e-1a37-5e8b-83bd-b0ba44571f1e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9adf6210-afcf-5cb1-b65e-285cf5c5b541",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.5 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@6.1.20-tuxcare.5"
    }
  ]
}