{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c2cdfc7e-a822-514f-9e8f-c7b820bdaebd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "6.1.20-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:90e23eb7-7280-503f-9d82-c9adc5a23ba0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6134b2bf-e36e-5864-8b0c-2082ceb49d31",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7b8836f-757e-5f38-bddc-ec46bf39aaa2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0bb3027-3a64-5069-9114-67c474c1dffa",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e3b365b-f039-5b77-8afb-8af2acfeefd2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09a437c5-e987-5dd5-99f3-93ce4b52c91c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6168290-672d-50d6-94c2-530a3e812eca",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a86958-cbd4-5b7d-ad9a-cc0a459a1673",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed98c8a2-9fec-5a03-9622-a5d6d6485d70",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c2c41e8-c1b6-5f87-803b-d692ed9e2338",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7649f5f-55a8-5303-80f4-edbf1c8c631c",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d2aca16-5a1d-54fa-8be4-2b820f2a3479",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473c68c9-10c7-5dd2-a2fe-18ef0926c71b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.6 of org.springframework:spring-web. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f848ae80-4f06-5f2e-a735-27e5141a2833",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6aa5f06-0eb2-5fe6-9ec8-65ff53981fa6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e5a63b-e9af-56a4-b94d-1985e349821f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01242563-6733-5ab2-8919-7380f669aca3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa8323a4-47fa-5f8c-a39f-00ecd6f40ccc",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59f27cbd-77a6-5472-8380-370d86915452",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b84e84b7-73fe-5dcc-97e3-8216c1ff29e7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95db50d-83b7-55ab-8dd8-6898c618771e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:894c65dd-34f2-560a-a0e4-2965976fc114",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b43caa5-55de-5960-947e-da273bef4036",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a90661-2acf-5919-88ce-63f0b41daba1",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7caedb10-e8f6-540f-9fb0-2b0a870bf338",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.6 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@6.1.20-tuxcare.6"
    }
  ]
}