{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f8c59629-8d73-5dea-8c49-deca46210738",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4",
      "version": "5.1.5.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:20de8aa8-c40f-547c-9a48-5236b67606f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:feff70ec-8433-5ad2-8d18-35f75caf952f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9021ea94-63cc-5578-982c-24a5f3d4c6ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3ef9a9e0-ad4a-53c0-857d-68688c446ec7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:911da8e1-7c81-5393-a2cb-b96923f54ad8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fb8e07fa-7af5-5e3e-bdce-5b810ca00acb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cc6b223b-0d4a-5cb9-814e-3e2b7a23e32c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:af2d566a-b1d0-5055-8ced-54cac3381b5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:694328e4-3af8-5e27-9f20-81e63f28e81d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:54dc165e-4851-5fff-8403-cc252c5dc613",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cd4db4c1-fd69-50c3-81cf-3296a7e7bc47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:eb3db4c5-9583-56d7-ae1b-72419d0fb867",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f3fbc74f-2a5c-5d39-9cdf-3b74e9526d76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7c713aaa-b2d4-5bb5-8edb-90071e8cae74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:64b61838-a0f6-5c45-b41b-7709253b1e15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2664ba3b-4746-587e-9899-afeb9a6e7f47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:42408c7d-6a2d-5ce3-9caf-8d59237a49ce",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-expression 5.1.5.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6f7d6a52-9fb8-504f-bcc7-b6ff8e5347cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3e25f440-f9ba-57b9-af34-9dfcd49e5bb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4abac6f9-e386-5b45-b373-71be95f227bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0d56f391-77f5-5c1f-ab67-02b498adc771",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5b324984-2fdc-5609-b583-16bbf0f30493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1125cce2-a561-54f5-bf71-101f734d1d21",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c891742-7b2a-5881-99ce-301c8901df4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e21a8b36-772f-5b59-aeea-a0cd9b0ed4cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:05efa26b-daa0-5765-bd05-e0afb6760b3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:99219920-475e-5a97-b20e-845733e75c37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:be29cd43-8cd9-5f87-96ee-ad89c586233c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9ea96dbd-6cc3-54d7-89da-78efdf14be0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:783b9bf5-b688-569d-bd39-50594b8584de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3c6410a1-22c6-58d9-a0d6-a8ef2cf849b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9e5be37f-9138-51bc-9865-f24f9b105a89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:47685204-819a-576d-a6f5-e78d2ee10c61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6e1c0a30-56c4-5196-bdef-2bfb165b99d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65078f6d-ccb1-5574-8a7d-e2fd8e6ec39a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d7420c03-5709-5090-9330-738893afe1be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a6999cb3-6529-5b04-8190-b239b16ca0e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e9a827f2-7a56-5865-ab54-16dd16d98b0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:502e69fb-6a61-5d07-aa36-571a0b2319e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:20ff87b5-3b40-502e-84c3-f16808173199",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3b405d92-f626-5c17-afa7-dc0f6bd99ac6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6bdb7eb1-c53f-5ddd-b973-a06fa6f0d980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6d9b776b-0c39-5324-bbd0-97392cb1deaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:eeaff040-e88d-5264-a795-a18147c0a596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:40097be2-24ce-5327-8a0f-e58fd13549aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dec9500a-fb0f-583e-843f-2477b96f3e49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b7d22855-e97e-500b-9c4a-042f9ef2bf00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:95a1dd24-ad31-580c-a29b-1ef602ba4656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0e9e42a3-6d5c-54ce-ab7c-14cd7d50a68c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2ba828f0-500b-5773-a1a0-04f7a111c70e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b2d26325-ee9a-5f70-a972-6559dbdf2a4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:045709d5-a797-5afb-8501-45d0d4093b7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a8cd0be0-10a8-52b5-96eb-9582e21d7f6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:454223ef-e972-538a-a8eb-87226039b1b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ba011ba6-e2cf-55e8-8af8-b319282186fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0fb2c477-8246-53ff-8243-7c97bdbdeac0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e5284a78-0108-59bb-97ad-c1450b76e315",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4536dac3-6d1a-556e-9343-b4437940448d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7d19cdb5-e981-5eda-b34a-f20da696a127",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.4"
    }
  ]
}