{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9f1d6038-6b85-549a-8897-7e5f293a8cfa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "6.1.21-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fec4be91-6e23-573b-acf7-3d7427cb9205",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d13e4ce-b2f7-5185-9fdb-13d8cd3f8bb4",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4170774e-3f77-5020-a9c5-2fd5c6c75e3f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12df59bc-4332-59d8-b5c5-b9e04cf64514",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3131afe7-4478-5644-b78c-dfa6334256d9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4833fd9f-3606-54dd-8b1a-5466796099fe",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bb7c2b8-cb85-5cd7-a684-0edf644758d4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:433344da-57ff-58a9-aaf7-62e114f29294",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85176c07-fb2c-5e94-a417-30853b13138f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:798510b5-5b21-51e0-802a-118a7d0e3146",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca853d81-8c60-53bf-b018-fa25cfd8c7a8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005b7e5c-d364-50eb-a07c-e6ec9b9f02cd",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0295f5fa-50a4-5727-83d8-fe80f1758712",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f7f148d-1f1f-5952-af96-65ae20c71b49",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fcce501-c6cc-5e54-9cc5-e6558e7be1d0",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66b903a3-14ff-5030-9681-7dff5ecbe38b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64cbaf7a-3f8a-5bd0-9cdb-354851b706f4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fbac1b3-da93-570a-91ab-a41109fd2217",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fe7fbee-77a0-56a0-b4a3-567a92d77933",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:576de1c2-ba2c-5858-ab57-6dd085bd6a1c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:354f02b4-2258-5b09-9b52-386909813683",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce63b77f-bc16-568c-b184-42f5589ee314",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e355a2e3-7eec-5991-bf43-76a3f28447f3",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ee96fb3-29c1-5dee-b954-e549caa27c74",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae544321-3d31-566c-bdba-b24f0c898da1",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2eadb66-9c61-503b-b2ca-d1739fc90a32",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b471e50e-9931-553c-b5fe-b48e82e57680",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7e035ea-8ec2-590c-9687-76824484f0ca",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bcf3aa2-0012-5fe6-8a73-9c720af12c43",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e151e520-2b4a-5ec7-aeb7-ab558e6a385d",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbbb6d8a-4961-54cf-b63d-4ab1b084d35e",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:685a510e-f1d3-599c-805d-17a6721cc405",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe9b5411-98be-5af6-aa29-e84f7de090ed",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a05fc7d-7495-5422-9d97-f670abb0ef77",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a8e25b9-fa21-55a1-a6d4-1419aa5c101c",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e474678-a5d6-56de-8e3f-66c385982674",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb9ad084-cbba-5338-8b76-9730b6bad52f",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d18b35-6c17-5d11-abb7-d4173222ff23",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13312300-c19f-54f9-8871-4c60b1b5ef92",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.21-tuxcare.3 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.21-tuxcare.3"
    }
  ]
}