{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2cb1e0f5-12aa-59b6-8bca-f4584b4876ea",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jcl",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4",
      "version": "5.1.5.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a0802fe1-de9d-52d5-b1a4-e3adf170e9b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:11fafb55-eb7a-5f3a-bdce-9e0a808c755b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e60a2f8d-ac24-5639-8ea2-8d3ba9c6b09a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a344c2ea-fe4b-5f50-9990-36a753c83a65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2f34e3b4-9cf0-5377-bab8-3045a2d5934c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b505ac85-8640-57ae-ae2e-5f565cba3f75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d755b610-0130-5785-8d4f-bd5c0d7d5eae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e3766d5e-933a-5c3d-8862-f51c8f5f63f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cd43de17-b5ac-5d96-8285-97fdc65c8cb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:84486b49-ac3e-5310-b0e4-8891cfc07a49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dc506e16-c3f2-5a59-a576-21bd1136de63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:99d9f373-b956-527c-a1b2-558d50a1e2e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:411768c4-f9de-59bf-8e84-265ee8a0062d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8ea0dd2b-9d27-5eaf-84ab-ff502d53e698",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:835b1e12-fe02-56b7-934d-0f836cf37e51",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a0d605b3-2801-55d2-9007-7a1f8668c067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:76a8bb12-276c-5251-ba07-1874a7830927",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-jcl 5.1.5.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cc4fbd44-7876-519b-890b-c66470f361db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:66aa54f2-e4b4-589f-807a-b8609bbfe9cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:941e83a8-8660-5540-b967-be3184bbeebf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ea03eb46-18e8-58a9-8320-e1eabd3cade2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:94fc5b8f-8713-5d16-a0d3-dd68616604f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6f354b57-3511-55fb-8c9d-2d3ab31f3666",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65aaa607-aab4-5617-aab7-08bfdfc657ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:989f5bf3-6b8c-58bb-a4c0-8a461fc7b882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:98429a7c-2af0-5bc8-8f0a-b177a83e11d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6d905c99-150c-5b96-a247-4240496edcf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1e059a21-778e-58be-b517-073cdb73ab34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c0d3119d-34e5-58e1-957a-253eb48029dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b80d2dca-6312-5c96-b753-09323fdc10d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1c089ccb-306b-5aaa-9a64-3e781ee61bbf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e3de006c-8b28-5da0-b337-c1f7d60fffb8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1b8909b2-c8eb-5686-8055-7fecdeed2c1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:56addd09-27b0-5480-b185-b8257f008909",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d31c5225-cd16-5bf1-8ce9-c983f9bdaa61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f414295f-6b3f-53ae-b949-52e6c028808c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e7a35341-dc5f-5ae3-9fce-7ed023325a8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e0faf5cc-8e46-584a-9682-edd1f90ec7ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d0fd0820-e43c-51fb-941e-ea7fe4b61034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5c16d402-d8d7-5da4-8699-547e2b60e75c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:22e67004-b13e-533e-aa67-785e7491e055",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:68ad6bd6-6652-55da-975f-626230500aa9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5ce35abc-e260-52b0-8539-74ad03f337d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ac1542ec-96a9-5b6d-9210-53bf75054bd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:55f1a2a3-8aed-537b-9dc3-2714323bd698",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0ca0d681-e536-5b5e-b3b6-dc9df78c434e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f29dce81-e72c-5dd2-bb21-574d218809c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:73924442-78d4-55ad-9202-642e2ccbb9f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:69958766-a0a6-5094-9370-d74c949c7dcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0a0c192c-c26c-5419-8816-a04071ad1ea5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:91bfbb80-7846-5d67-8ba6-9d33bddcd7be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7169be3a-d097-50b5-b5bf-cc96d435dabf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e898b5e8-6307-5a99-9711-2751ac902891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2f753b68-b320-5014-a2b1-5b51e9020c9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9be15702-6110-5b88-8794-4217916872b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:62db6c73-59f9-55bd-903a-f6c43d80430d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c5ef6c91-7dc8-54e3-8a50-0791418f84b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:76fcded3-b0a9-566a-80c3-5f546bb9dba3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bdbb3050-0cc4-543b-afce-6d66d44e3f21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-jcl."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.1.5.RELEASE-tuxcare.4"
    }
  ]
}