{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c647444d-4754-5be6-92c8-b0d008b0b59f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4",
      "version": "5.1.5.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:957ac471-19b5-52fe-acd5-d38545a436a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:61cd37da-c8a5-57e9-96bd-4f6511fbcd1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b6f71759-919d-5174-8e5d-9a0b0c840451",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e409022e-6984-59df-823c-edda1b8b6cb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:93ecde1c-ec70-5ec3-8d3b-ef6b2c4ea01a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ebbf6a35-48f4-5a38-809b-b3d56aff39a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a0b10a24-2023-58fd-b10a-57d26752bcae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9fc32cfa-1899-523f-a2c2-89858ace4bf2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3d2baacd-2785-5fae-a099-503d13630e84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1296a2be-4830-5b37-a16f-ba250703f6cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:73eda9a6-e4bd-58a8-b4bc-8cbafd83d7b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1f8b2eb0-e9c9-504c-89a1-ed2106aad5ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1574597a-2428-5496-b405-30cd8068d592",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aa071dc0-7240-5230-957a-28b351532a8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b16dc871-6629-527c-b961-02016653f0c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:680ae47e-15b1-52b0-ab53-3300626e957e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c9a6d482-d025-54ff-bbaa-4c9566509b35",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-framework-bom 5.1.5.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:53bda335-4bd7-5068-ac87-480e0f8f5cbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:89aea25b-ca31-57af-bb83-9287c507eb97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:90785009-a43d-5a82-a17a-ffe69341ca2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6b21ec72-f839-5f3c-8394-547f5b5dbf4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:75f79e0c-5020-5de8-bbc4-995ee5f06958",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c939f595-65c5-55d8-8846-f679bdf11c01",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b71dc47b-c115-5fac-9ca7-f8487e4a45a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:58b72a9f-a42c-5f16-8b00-654dc8ae29d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c8b113fb-ec95-59bc-ae64-074b875d341c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7de03c8a-ad6e-5d09-ba7c-ab2530282760",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:993c2fc0-ea0c-5125-b618-678a608ded44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b21c79a5-5e3d-5c10-b06a-f82b72139551",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:eb315184-3bd7-55f1-b03d-1c67f25a23b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b2b2ab66-b6c4-56ba-a7e5-b6ede1b8e7b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4eea45b6-8e87-5500-bfae-545ff7eef311",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7ac5a8fe-1d59-5a02-a076-eed8a3fc19fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c1ad108-82d4-5a3b-a2a2-ce56e2ed9edb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8f8b8994-fd0c-5577-bfcf-881833275ecb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b27fb5e2-2835-5122-8ff7-5b213ee929bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7f0515ae-347c-5b09-8b45-76ecda6ac5e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:827e8bda-173a-5fdc-a7b0-fd170abb9f92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3b9f22f5-ac57-58e5-88eb-7f3b62b9a60a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:abf5c054-ff72-5f4c-8940-0fb33a476bcc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0f1b4d52-b056-5d11-bb26-58045ed7a6db",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6938a84c-035f-5557-893c-0b295f23fd38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:46876005-2a2a-5bd0-a73d-3b39cfe154f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f6619108-8f8d-5cfb-ab7e-be4ff62d3c01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3d130080-b991-5a17-ae75-db04cac13950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e5daf7ec-0354-5337-8ae4-60171591fc3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5a0d8437-94ae-5bf9-bf07-a58d4ae17c40",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e5ddc775-0aed-5e0f-9584-2553bbbbebc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:20863ed9-2261-5b79-ad87-54c7ce7eeb23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9bf7ad88-4212-54f2-a5d7-da67ee5a647e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b7bd278c-e313-596a-a678-183917646854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fee3acd8-be61-5934-a8fa-846e27d5d032",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9e5406ec-af15-544f-a5f5-d5ce1ecf80f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:59109321-7e9d-5213-aeb4-e0de2107f796",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:439f9e3f-c90c-532a-b1ba-94caa75e3e42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b7897bdd-53bb-57b8-a120-da4b2b400058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bcb1e17b-98db-5c41-a756-526393febda8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8127ad31-27ee-5de3-9048-70a9316b464e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9e90210a-3379-5ef3-ae60-08bca4bdfa3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.1.5.RELEASE-tuxcare.4"
    }
  ]
}