{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1286ea25-c197-582d-9074-d9fcf9fed1b8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4",
      "version": "5.1.20.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cb7d36ba-ee86-5953-8c85-97f21812c30b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:df105c3d-cfcf-5ccd-8ae4-c6dd1163cc04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b628c3b1-bbb1-53de-be32-f932b3ebdb9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a2100fc9-f147-5c19-82d4-37390ad88c20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:42c88cfa-8524-594e-9204-5c8a7bb64bb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ab9b8ccb-0c8c-5de2-b346-ed7229385584",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e167eced-4f78-563e-885e-66617fda22f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fbea56ca-0713-501a-8090-ab9b0b917a90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a264cd17-c732-51e5-aff4-c39951b7900c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f6814729-eaaa-5622-9ece-e406e94a46c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:487d0f50-5042-5e50-98cb-8c93a01e9732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:59574547-3bd8-50c7-97f7-53045c562105",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d171ea03-c2fb-51bb-b639-690df737f04b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dd88fc1c-3d52-53e1-bc4f-2d12308168a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a5132174-abbd-5257-bda4-bd59cb7a9fd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:709262d7-27b7-54e1-8be1-29fe74278135",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-core 5.1.20.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:062ac194-d790-529a-b5ea-779083b14f0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6e6de8dd-04f2-58f0-afdd-0868e1ba7132",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9569d93e-c7e4-518f-9b14-9723d5aa6029",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1daf05a5-2e60-5581-84d6-fb83301408ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:49a8f28d-ad5c-515e-9e6a-cbc391bae77a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0019c5e3-7e4c-531a-a3b6-3beb703456d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:81914991-b1c1-55e4-bdd1-45002cb26ad6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:28fc13d3-9f9a-58d8-828b-ec6ec6b3dd5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:74b4a337-eeec-59b8-89b0-443cad7d331e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:94697771-aa44-5e3f-8aee-f68c7af7c74c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ea85ef94-ef91-5fe2-9501-1192ed9726d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d1a85b4b-1b0f-507e-be55-f24bdc9fdd79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8f0e10e4-28e4-5e6a-bc3f-50ef9eb6df0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7caaf7e0-6bd4-5a4e-9ce3-34f84c32537a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:592eeb76-dedb-5613-a0f4-c8400b1c6de7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c9ffde0c-9be8-5bde-9c01-aa60df39b8cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0a8b0f3b-5826-56c3-b345-fa5ab00ff5e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b110471d-3d32-5207-aa19-1e327c42b160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:962bad20-a34f-59d2-a475-752e68b7c97f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f2cf71f4-6aee-5a53-ac7d-2d19b6209aed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0fddf573-87e7-5e58-8897-cd4fde0a882d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e6fbb91a-d5ec-5157-bc5b-4f4fbeeacf5a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e820cb4d-7d86-5d4d-89ad-59d7c09b4f43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ec710d8c-bd76-53c3-82dd-f536b544f878",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0645e6f1-7e7b-5c24-baf8-659bc073b690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fe72cbfe-6c24-5c4a-9726-f80a7b1788d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5534df0a-5a2b-5143-b8b7-0e22cb8d63fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2a9ce517-24b7-52ab-a244-83007402701e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:85b66e3c-2025-579d-9b2f-f463130513a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1dce26a2-9362-5429-99cd-206f0b4ab7e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a6079235-0b6d-5832-b85c-a9013f51eb24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:61cca1d6-e405-5708-b527-cfff97f3f21a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ccf6585a-bb08-5060-bc4e-257a5683b557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:01282124-db81-5b4c-ab0d-e69d65789ed4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c12323f7-8b84-5fa9-a6a9-7157bd3945ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9d4035c3-a5f8-5672-a600-b5a0ea3c0b44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:51db3605-8b31-5a4b-a124-633bd7e4187c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:098ee675-60dd-5134-95dd-dd796f09ae28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:58e69de0-916b-53da-9199-4cebd7a805ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9744a4e2-0771-57bb-9de8-e75981bbd3d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.20.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.4"
    }
  ]
}