{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ef8ba2d3-33ab-5427-97a9-b6b05882f7dc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "6.1.20-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bb7d7111-2ddc-527f-9d25-ceadceceb5c7",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06904fd-6133-5984-815c-b12d8bc71f85",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2bbeb66-af87-5daf-9e7a-84de4c4a5c4e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c66f199f-359b-50a2-9277-49c58b0aab62",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5244c6d-286a-521c-8364-3e32166e92b1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:937acbbe-d398-5340-9ea0-9597f4515fb3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ac66459-ebee-5cdd-b743-a16915250a48",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c95a862e-5dc2-5698-94bd-801ffaf4c3e8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a232d5b3-9bf4-56ad-950b-320b5b4cb208",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f18d50cf-b50e-52db-ab30-4e584029f7df",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb6aa0e-94b2-5211-a086-7ea6a46a5987",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e66b19f-04aa-59d3-a41f-3d196d22daea",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ad8d04d-5fe9-504b-bfbc-0fa21516436b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28782f6c-8ad9-58de-85a6-3b064f245908",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e81a82b8-7eb4-520a-a674-0421aff33f2d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:499b4783-0b58-5e99-ab38-8397e67b001e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a998eb28-f55a-5b57-a4c7-13bcdb5a697e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f99cdf60-23da-5fc8-ae2f-cec9c0551d55",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1f993cb-6d44-56c9-b25f-3e367e90262a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15fb57b-29d5-5a63-95ca-5265a38ab6ff",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dec40bb-33c6-5155-b947-e595afb8ca7f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:341d1a8e-ed8d-570d-8c87-b5d34f40d935",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2f99d71-4d44-5f30-819a-db218dd673a7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c8c03db-3dad-5e5d-a4df-99870e241723",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:428563bd-1be9-5a2f-992c-26ab95d5bfe2",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f24e2bf0-e78d-59c2-a8ac-a2ac79574e99",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f1b7219-2a65-5d6b-a6a2-88459f85a5b8",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cc143e1-fea6-581a-90f5-adfaaa151fc5",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5affb6d-cd3d-553e-a4bc-ebe3d2d0f68e",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881c2cbf-a273-5c42-b677-fa8957a6c556",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b752c82f-f575-5e5f-bd08-394e00603eef",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5939dc5b-0df6-5ed6-96e1-9aad2f18df6e",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d47ffb5-d12b-51c7-8245-5cae18595fa4",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93125863-a63b-5f42-9662-ef91ea7a879b",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7f7975a-b0ef-5dc5-8539-907d1547ab27",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06737387-7873-5eb4-982a-565f9c4340c7",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:731a3615-60ec-5c87-9e57-bdf1ceb4560d",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21bf0e0f-dc8d-5b9e-9705-86897f9eb910",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25f1a33b-8e6a-5568-901e-67eeeba92010",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29af19c3-ac56-518f-ac28-96c2ae58088e",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@6.1.20-tuxcare.9"
    }
  ]
}