{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3dc9c092-fb4e-5356-a9d5-081d0f8d538f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-web",
      "version": "6.1.21-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7eb6e8db-d132-52d4-a627-4fab1a20c204",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.9 of org.springframework:spring-web. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b3a5a1b-d732-566b-b233-f9b14cb7aa91",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c2b5ede-92b3-5c90-b9a5-69dfcd26fafd",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff781623-1112-55fa-b9a7-39f52c538c49",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2336559-df4a-534b-8fa1-66ab4232ea69",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a322ac3f-b046-5a5b-b17a-b4dea9cf9c22",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9102e07c-839c-5530-9573-4637264567d0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62edf82b-307d-506e-908a-1c382b903d75",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c789b44-43c0-5f31-9f77-ce58f756fb85",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8682d9b9-9433-548a-8f1c-b4fb5a290207",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0b4e2f9-27d2-5e65-ab92-25ace815e1c8",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1402593a-d29d-5c1a-95f3-eac82bbf04cc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419f4122-a4d8-5c55-974c-c8cfba8d3d72",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2fb3d21-ab77-5354-8884-7b87c2dd52dd",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a4cc5be-edea-5619-b7de-1e6278ee3489",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c80ea3e3-7097-5217-8114-53ea85ad4c69",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e8910d6-46b0-5018-8cae-a4d8b034c594",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd0d38d8-607b-55c1-973b-3d6c52d2a0b3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc9d768a-139c-5bc7-a158-69e373003fe7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e49f7292-2311-5ae8-9ea0-5be492b239b5",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0b1ce6c-dd39-5e07-849d-8226aad90fb8",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70a05d7d-fc8a-5e60-a9cd-5363ffaa24e9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8b3472-9723-553f-842c-6f94252a8d40",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e7e8bb-440f-5cfb-aa06-569929980907",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a43579-be08-5cf4-85f7-35dcfcf5d610",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cacba220-59dd-5327-acb2-dd4cd2769af8",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc939f3-21ac-59b9-992c-ca2a133f54cb",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f760f4-1ca4-5c01-989a-89673439b66b",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30ea85e2-ffec-5d9b-9177-8f0b3222ad2d",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f847d4c2-1546-5b90-8974-4b542b28c221",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1300f2b5-810a-5e05-9da8-6643f4f14ba7",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29afe73-9d9f-5ca0-b09b-afcc5f0a485f",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:390ede5a-c7c3-524f-a597-4b9ec18e6ca8",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82bceee-f370-5f18-aa8d-fda36eb8bf2d",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfcce25c-8cbd-5017-b5b2-50b6b98630c0",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80a33b0-4d4d-5380-956c-ee22bf05c9cd",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cbeb5d7-99ba-52ad-a878-d1975b3e9ec0",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17fc52cf-c0c8-5307-a9ef-731d05dcbf42",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c9a9232-8369-5049-b89b-1dc11291cdbf",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.21-tuxcare.9 of org.springframework:spring-web."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@6.1.21-tuxcare.9"
    }
  ]
}