{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:37e49f9d-a467-543f-a8fc-c38369d508da",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11",
      "version": "6.1.20-tuxcare.11",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:cafd0e1c-1ba0-54ca-a369-cb73cea3c489",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e037893b-5bc0-580d-a0ea-40416fa9be04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:73cdba57-58bb-5f72-8f06-728eb468d66f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:9074e3e1-3ff9-5f1d-a106-337296c0b4bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:68c53c2b-7002-54da-9931-d99aecb2d285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:1422ff6f-8baf-5068-b8f5-7aa29209c1ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:180ca070-be4f-54f6-8245-cccbd06dc061",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:b92f5d3f-d848-52c1-97fc-da9c1590e695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7a781796-559d-5d00-94c7-f48973b195ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7529ce5b-8897-5116-9451-174e702e3be2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:615d04f1-0c1a-5000-8f68-e1a2dace0531",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:049f4019-500d-55ec-8de2-df6a348af287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:69065534-9211-5932-be63-a94ce8bf0d91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:19fca4fb-5a69-5cf9-a735-800758f90492",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:38f51f51-f734-5d09-99f9-a8183944306d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a150f997-6ed7-5b37-b1c0-06d59028d52e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:897c54d8-ee1b-57a7-8dc6-fe7876537661",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7ac863ed-1e70-5c81-b852-73a020300e2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:93aa5441-904d-5eeb-9a56-aff5da47a357",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:9ab1c502-6113-52a6-95a0-9b89af672e25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:090fe206-2c9e-542c-b6c8-ef34e5c3f6f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:4ccc89fc-858f-5527-9ad9-beb3780e8819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7c769aa7-b06d-5848-a747-8e6fec2c4ab3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:621024f7-5535-591a-a852-921223a5eaaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:81b6d6cd-a84f-585a-a3bd-9f518fabd178",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:99bffcca-7163-5e01-9eb6-efec7c9e1836",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:3a40b827-952a-5161-af52-f295cbac079a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47885",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:88f7df41-2f64-526d-a04a-986796c34667",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:683ec2e4-8b83-52e8-a1c4-2b7c72a922ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:db4049b9-36c6-5a62-ac3e-d434725e3365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:34888be8-98f4-5632-ac15-d323d4fa48e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:3a76400a-f4e8-5cf2-a0cf-f8cd97ff4f26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:086c2ba9-29c1-5b42-b6eb-354c2a7528c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7fb4b796-d1f1-58b4-89e2-e7c7206bedf3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a970804d-90a8-5a17-a165-fb2fcbc32964",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:bb902c2b-fd91-5ee4-b5cd-600d0d8d25a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:38bb2857-a97d-5464-a654-b47079d6c45b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:eb81d5d0-94a4-5806-9d09-c5b934da6b5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:0fbecb9f-ccce-5f97-adc8-9d750f7f29f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7e53a739-d06a-5a92-9fb2-a589ddf4d883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@6.1.20-tuxcare.11"
    }
  ]
}