{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:88871941-e31a-5979-95a1-050427735235",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "6.1.21-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bd98248b-ca21-5606-ba7a-23b5b030d8ff",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0320793-219f-52a7-99e1-868eeb70e738",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2154070d-0fc7-5d8b-8a94-37f2fd27bc60",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b6769ac-d9ef-526a-98e0-68c5961f1f8e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b84841-f7fe-586a-82c5-f3f347910a17",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec2a47a1-516d-52e8-b566-24fa11b7c0c0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49fbcb1-f321-5ebc-874a-ccc5a321a79a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34b28fbb-4375-5f2b-b397-533394112b52",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b2ccbd-e43b-5d55-b48a-78a2525ae8d7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2d149a9-1ad6-5ae1-a27c-28ec9d194a13",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff09535-54f8-5cc9-81e0-756725af7bc6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcecd4f7-c1d9-523e-9d5a-cf7b3bb7021e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dfb4701-149f-514c-ac80-e46cce927862",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b97a9924-859b-59dc-9f8c-aa6d8eea4bde",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badc2a45-b854-5177-9df4-42e24080dc9c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:353cc093-eb9e-5d21-a8b4-400d98b4136f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44c39a73-679d-59c8-a118-5e4fff477656",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2095596c-20bc-5375-b045-981faf6a6eae",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c962a6a-d881-5b58-97e4-a60747b71ab4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a614b0ea-cf25-5ca9-a911-21c80942b0cf",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cf20bd5-ce63-50b5-b163-0bf09727066f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852c5532-574c-5445-a845-ffc68c8c6a35",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d360e5-1bb5-546d-a1e5-ffee0eace2e1",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4eb59f8-bffe-5eb6-81ed-6afb2dd756b7",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:553e928d-5462-540c-af47-68ccc677742b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.21-tuxcare.8"
    }
  ]
}