{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c53d5529-ea47-5113-bacb-f870db98adaf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "6.1.20-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98472bab-c4d2-5e1f-8ccc-21ce435e9b8e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8912f523-4c55-5ee7-bfeb-5364708a39f0",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7341659c-03da-5305-b1ae-ec6bd7be2fc2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9526536-bbba-5530-b21f-23ad4b781269",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cbe8ae2-1ec7-5b67-8e3d-566ba1805782",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce6a431-205e-507a-987e-5ad0e686e278",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cabba96-bace-5ec9-87e3-395ea7cbbb1f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88476a45-73e7-51be-a80b-81a5f41832c1",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45ca82cf-f738-5225-ad28-c35f9800a90a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:612d65c6-ed2d-5e2f-af31-af1ced4ca8cd",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bf29840-252d-511d-bd6f-c9fd9d2f758b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:431330f5-0cbd-50ea-8c83-385e2a1432a0",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:010f8fc9-6cd7-5412-adc7-a4a4a15b0cf0",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ec959e-19a8-5c84-bd0a-51709da57818",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d0bda57-e2fb-519c-a8fa-6a23524e1aeb",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ca2100e-a0c1-58ec-be2f-8a9ea61b02ad",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c61b08e-5e46-5de9-917b-ae0d73fdbd49",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:039ddbd6-322f-5b19-a6d7-48b17c3f3844",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc097cf8-f8f2-5ffb-b9b3-3bf5807d9887",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9207e25b-3a0f-57fc-9fae-94d12ca60f2d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ba202b6-3ddd-5341-a71b-d2817201968c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af4cca8b-4b3f-533c-be78-884337eeb053",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bed4907a-72ea-5aec-8d65-5368b0c0169e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd3c19c-42f0-58f6-9f23-15b652a9b82a",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfd44869-c5c8-5b87-80b2-cee0a41c4248",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54a6b04d-e8e8-5b00-a5b1-d02492605a4e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.8"
    }
  ]
}