{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4932204b-85b2-5850-afad-8d3d265ee321",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "6.1.20-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d27b2d61-ab9b-5c58-bf7e-e2b910ae33a2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d361e3-7c8f-503f-9d40-0f638c6dd4e9",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10539647-c53c-5466-bbff-524c0e0fa7a5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad4fa5a7-c570-5272-988a-c3683bde2bab",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af6b165b-71f2-53f9-8484-f8b9cb03f078",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5594db2e-a484-50d7-ac23-3aa102828100",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3dfd237-d0f6-5b21-8500-356de43ce3d2",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b15d6da3-ece3-5b44-a611-2fd821aff518",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f52ad69-ea95-5bbb-8f0f-47dd7e80e27e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b56a370-dae5-536b-9401-fe738868fc45",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2acefe8f-df29-5d94-ab62-5e6dfb78ec6e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d2eef7-c025-5b0d-85e9-ca07d8014243",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94403d36-be6e-5d76-bd5e-f479c948d18b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.6 of org.springframework:spring-oxm. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:931993e4-65c4-5f8d-812c-205a5c28d06d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2854c5ff-5fe1-503f-9b84-2b1c9fb5c829",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29fa24c5-84c8-563d-9a66-eade66adbe4b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdbdcd7a-8eb1-5d2c-8579-c590c5d71271",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30eaae2a-b0c5-5c5e-95d4-b1922f956fde",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9117694-dc6d-51e6-923d-46534f1caa87",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b105c5b-39c3-578b-bc2e-55eced181207",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4863fc55-8cf7-542c-a2f6-6575625fce08",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b53db4f3-6412-50af-b3e6-dd9242f7ea1d",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf86b83-f253-516a-965b-d5ffacd70349",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aa4a10e-626d-5871-b056-7855b81647e2",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f7059c-37c6-54ed-a999-b3b2f55cd9f2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.6 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@6.1.20-tuxcare.6"
    }
  ]
}