{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:153fc795-b334-586a-940c-6626d6e02bf8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "6.1.20-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c5ce93c3-6e6b-5f7d-b8c0-3c5479d02759",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0738ff38-433b-5dd3-8ab5-0cc99a69657a",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948283b8-bc5f-54b8-8d29-654a19e1e5e2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293d99ef-3b04-587e-a605-7bd63636750f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:065faa74-2b88-504f-98b0-31ba41889902",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40332340-9977-560a-b3ec-8e028c62e4de",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a70d3fba-221f-54df-a1b7-8fd5edc90242",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196a9254-35c3-5a59-8eb5-e09948b1b5b9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:204b973d-3267-5f70-92da-907b74e50758",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6975b0ec-f53b-565f-96fa-aabdd763d13f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9449a0fc-1ead-5bd2-a74b-3bbbcfe93c8b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7941cbf-f874-50a7-b2c5-b19facd47c29",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cb3f3c3-d869-590e-9d2b-b12758c10092",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6f0bb5f-0d1c-5ac2-b487-e4333caec0c1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b8f52f-820e-5a4d-8014-f0a373c8beca",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dd90fe1-4572-5daf-a8bc-c7f71629d855",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f400a771-ab2c-5fdf-9b2b-8427331a8c2c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3f44978-a8d4-5113-a98a-484d365d38fd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0300479b-ea08-5251-8a42-a807b4d6fe9f",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3310a952-4cbe-5ccc-9eff-d6ebedc58663",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7e084e2-fb7f-5495-ac07-4d90af5fc7b9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b7e8c7e-acaa-5906-a851-4b1270afd7bf",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bdb7ad-619b-50a4-862a-78e84911b834",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ea5f08-4919-55a6-b8b7-4b8db0655108",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bc69a2-cdeb-55ea-8ace-4fc6b696b653",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b0e5339-f544-5075-b99d-8676fce76eaf",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@6.1.20-tuxcare.8"
    }
  ]
}