{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:99dd8235-2933-5dec-80a7-7d77342b2711",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "6.1.20-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:95e8f77d-71a8-5087-beac-5960428bd2cf",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45833f74-8614-5ba2-ba35-d93515749fd9",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f017da16-202c-53a7-a855-8aa590b05b3e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ed166fc-3b6a-5560-845f-743d120854e1",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e47b741-fad6-55ed-a262-8e5ea71d318f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d52dd3-9adc-53dc-b9de-519e529e949a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b35ada5-75cf-5dde-af88-041cb2dcde9f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d97e9b87-80ef-5588-860a-6b266e9c8c1a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51dccf25-bd18-58e8-bf4c-9c7189bbcd37",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:063588d9-5ae5-58d4-ad2d-a4c049a9f0a0",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:815a21d3-2384-5533-8e14-d1d70859b1fa",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3694d1a4-c168-51f3-a692-43004153ef75",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7269d7c-d994-5fcf-8a73-4cf8a9facdfc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7509b3e-f5b1-5356-a00b-c245462feca2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bfbfdf3-6be4-52a2-a263-077877618474",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b7854a-98e2-57af-9598-0835ba5aa3b1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6f220c8-2a2e-5e4f-bad1-2592263003a1",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d154198a-f8b7-56cc-8838-546ba45413ec",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aece0be-1f42-51f2-82aa-3be13eaac6ce",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:181ba3f2-1d12-5e49-8068-575bc0e38310",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:332e9648-6591-582b-a240-f0a4f7263583",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4a6e788-755c-57ca-b8d2-28ab81e83052",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9334fd56-899b-58df-acd9-227ea997fda2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab29c19-109c-5301-a9a3-81ed9c9b41a8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9abe6ad2-176c-5a70-9fab-dd05ae2ae636",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.6 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@6.1.20-tuxcare.6"
    }
  ]
}