{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3ba65a92-104b-52e3-9a19-53bdd1ead569",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "6.1.20-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c5ce93c3-6e6b-5f7d-b8c0-3c5479d02759",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0738ff38-433b-5dd3-8ab5-0cc99a69657a",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948283b8-bc5f-54b8-8d29-654a19e1e5e2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293d99ef-3b04-587e-a605-7bd63636750f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:065faa74-2b88-504f-98b0-31ba41889902",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40332340-9977-560a-b3ec-8e028c62e4de",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a70d3fba-221f-54df-a1b7-8fd5edc90242",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196a9254-35c3-5a59-8eb5-e09948b1b5b9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:204b973d-3267-5f70-92da-907b74e50758",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6975b0ec-f53b-565f-96fa-aabdd763d13f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9449a0fc-1ead-5bd2-a74b-3bbbcfe93c8b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7941cbf-f874-50a7-b2c5-b19facd47c29",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cb3f3c3-d869-590e-9d2b-b12758c10092",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6f0bb5f-0d1c-5ac2-b487-e4333caec0c1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b8f52f-820e-5a4d-8014-f0a373c8beca",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dd90fe1-4572-5daf-a8bc-c7f71629d855",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f400a771-ab2c-5fdf-9b2b-8427331a8c2c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3f44978-a8d4-5113-a98a-484d365d38fd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0300479b-ea08-5251-8a42-a807b4d6fe9f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3310a952-4cbe-5ccc-9eff-d6ebedc58663",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7e084e2-fb7f-5495-ac07-4d90af5fc7b9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b7e8c7e-acaa-5906-a851-4b1270afd7bf",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bdb7ad-619b-50a4-862a-78e84911b834",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ea5f08-4919-55a6-b8b7-4b8db0655108",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bc69a2-cdeb-55ea-8ace-4fc6b696b653",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b0e5339-f544-5075-b99d-8676fce76eaf",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3bf9a07-9b30-54a9-8dec-21efe5015fec",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d25df591-6b75-52f8-a293-de14585a1992",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f41eee2-5e4a-5b7b-92ed-59388c61ff6b",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb4f7b02-c3e1-55f9-9e09-ca07da6569c5",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecff4db4-4c89-5c66-967d-cefdb0a5599b",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29c845ff-5df7-5653-a24a-2e20d30271d4",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf16bb29-5696-5fa3-bbc9-1399f21e3b76",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ade0450-3944-5437-ab1d-7d44304f41d2",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a4cf42-87c8-5272-813e-0f7a5a5e1f46",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dddd7aa-fa22-508b-852d-2138770c802d",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb9dc810-bafe-509f-814d-171009c1ecb9",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73bb5844-9e92-54f0-b966-69a871dd88f7",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bdb0603-e086-5d0f-8ce9-e34c5a8367a3",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdec6b26-ca25-54e6-a1bc-569b4715ecd5",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
    }
  ]
}