{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0c174c85-9e14-547d-a1c3-691827b3a21d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "6.1.21-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:77fc38b8-1ba9-5bd1-810d-b8c5ec4cedd7",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3ec9a6d-d5f6-5b21-80b6-5034d37967d7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0eebb19-dce2-5281-b5aa-1d3ac4ed6ee3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98f7a4e5-df83-5c72-aedd-443a18093bec",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0224e0f4-ff68-5600-9ecf-0ff9ce58ae36",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8a77497-a4d6-5d39-9357-ae19132f2d8b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e611bc6-a4b2-5865-b39e-a5af36cbbb21",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8c12d60-65e1-530e-8069-1f492839330c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf4e7dc0-7f58-59b8-9988-ea50ff24c37d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b269a241-9254-5291-a8c3-f58b3055cbe0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13214c4f-f9f0-5d5c-8e2d-59a6c2eb7af5",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f842065-d2a1-5a76-b1c5-cbcbb4bdfa5d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.7 of org.springframework:spring-web. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db64051-d5c2-5541-a0af-9ad15ad8d54c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e014f9f-07da-5371-a966-c631c441f055",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac6288ad-e02f-50ad-b309-dea2d13e7012",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:042199b8-31f4-59ff-a84e-6e98981d3e38",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95205c3-1575-5da3-b27e-2db7e3247f8a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d833d59a-b55c-51bd-a7f5-5874be9e954f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77ecdfe2-827d-54ba-a4ce-0c45cc90d887",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f3fbc2d-7778-5802-b0cc-6c04f67b9d2a",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bafb52d-ff1e-5a8d-8cbe-cb0e3cece450",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8136ddd-48d3-5ec2-8a79-161498b3c8ac",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14142ddc-8d7d-5a8e-b78d-02f8880cf5fb",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7b2f398-7fce-50d6-be3f-1ae20c480bf0",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.7"
    }
  ]
}