{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:66658437-62bf-532d-86ad-7fd395723aa6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1",
      "type": "library",
      "group": "org.springframework.cloud",
      "name": "spring-cloud-gateway-dependencies",
      "version": "3.1.9-tuxcare.1",
      "purl": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:77cb3474-26ba-5dfc-8f65-e78d27ec1df4",
      "id": "CVE-2025-41235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41235 affects version 3.1.9-tuxcare.1 of org.springframework.cloud:spring-cloud-gateway-dependencies."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bb24ab6-aa01-508a-8874-100c65c50b12",
      "id": "CVE-2025-41243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41243 affects version 3.1.9-tuxcare.1 of org.springframework.cloud:spring-cloud-gateway-dependencies."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c37499-5a6a-5479-b763-70878cc82b23",
      "id": "CVE-2025-41253",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41253 affects version 3.1.9-tuxcare.1 of org.springframework.cloud:spring-cloud-gateway-dependencies."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e506fcab-14e6-5153-ac03-6a7fa2e66a71",
      "id": "CVE-2026-22750",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22750 does not affect version 3.1.9-tuxcare.1 of org.springframework.cloud:spring-cloud-gateway-dependencies. Spring Cloud Gateway version 3.1.9-tuxcare.2 is not affected by CVE-2026-22750. This vulnerability requires the presence of Spring Boot SSL bundle integration code (spring.ssl.bundle configuration support), which does not exist in version 3.1.9. The CVE affects versions 4.2.x, 5.0.x (before 5.0.2), and 5.1.x (before 5.1.1) where SSL bundle support was implemented but misconfigured. Version 3.1.9 predates the introduction of SSL bundle support entirely and uses only the legacy spring.cloud.gateway.httpclient.ssl.* configuration mechanism."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85f69ff8-9492-53db-8a79-9b4da826962e",
      "id": "CVE-2026-47825",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47825 does not affect version 3.1.9-tuxcare.1 of org.springframework.cloud:spring-cloud-gateway-dependencies. already_fixed \u2014 The target repository (Spring Cloud Gateway 3.1.9-tuxcare.2) already contains the fix for CVE-2026-47825. The fix was backported in commit ce12c221 ('Backport CVE-2025-41235 to 3.1.9') dated March 19, 2026. Note: The patches provided for analysis were from the Cilium project (container networking) and are completely unrelated to this Spring Cloud Gateway vulnerability. The analysis was complete..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14b55630-762c-575f-a7f9-670281ecb555",
      "id": "CVE-2026-47879",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47879 affects version 3.1.9-tuxcare.1 of org.springframework.cloud:spring-cloud-gateway-dependencies."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.cloud/spring-cloud-gateway-dependencies@3.1.9-tuxcare.1"
    }
  ]
}