{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c26b1089-eab7-5e3d-ac53-6216a2521e7f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "6.1.21-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bd98248b-ca21-5606-ba7a-23b5b030d8ff",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0320793-219f-52a7-99e1-868eeb70e738",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2154070d-0fc7-5d8b-8a94-37f2fd27bc60",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b6769ac-d9ef-526a-98e0-68c5961f1f8e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec2a47a1-516d-52e8-b566-24fa11b7c0c0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49fbcb1-f321-5ebc-874a-ccc5a321a79a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34b28fbb-4375-5f2b-b397-533394112b52",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b2ccbd-e43b-5d55-b48a-78a2525ae8d7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2d149a9-1ad6-5ae1-a27c-28ec9d194a13",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff09535-54f8-5cc9-81e0-756725af7bc6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcecd4f7-c1d9-523e-9d5a-cf7b3bb7021e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dfb4701-149f-514c-ac80-e46cce927862",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b97a9924-859b-59dc-9f8c-aa6d8eea4bde",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badc2a45-b854-5177-9df4-42e24080dc9c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:353cc093-eb9e-5d21-a8b4-400d98b4136f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44c39a73-679d-59c8-a118-5e4fff477656",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2095596c-20bc-5375-b045-981faf6a6eae",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c962a6a-d881-5b58-97e4-a60747b71ab4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a614b0ea-cf25-5ca9-a911-21c80942b0cf",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cf20bd5-ce63-50b5-b163-0bf09727066f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852c5532-574c-5445-a845-ffc68c8c6a35",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d360e5-1bb5-546d-a1e5-ffee0eace2e1",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4eb59f8-bffe-5eb6-81ed-6afb2dd756b7",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:553e928d-5462-540c-af47-68ccc677742b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21551f6d-a155-53cc-be0e-fe5c5eb4e305",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccaa8dfc-1b89-5b10-b03a-52b7abdd5cca",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe4065e-22b8-545a-973e-158871e6c11c",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74954d66-fb8b-5788-913a-8e75dedbf132",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556b6756-40c6-553d-8aea-58e37d6b4cb3",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f21630e-a58e-5990-9d4e-99709342a5f2",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d914d419-0cc2-59f0-936d-dbec5d422408",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1975ab13-92d2-55f9-ab6f-8cc6a1a0f5d0",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23dbfc88-b732-546f-a8b0-807615a18023",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:265a378b-8586-50ac-87a7-72ef2c838287",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a0f72a-8b8f-5458-9259-04766a4f7bd4",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6877b5-afe2-56b1-bea2-805b748c2da5",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae8684c-7aa0-5d89-8008-fb660d9a3bd3",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060f394d-d851-51f0-b41c-b49c950bc14c",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
    }
  ]
}