{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2734f2cc-4ac8-5093-b9f2-82709c29ca62",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5",
      "version": "5.1.20.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3af597ff-cdba-5fd3-97f2-e5866b3c787d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:358035ac-f00c-57b1-88d9-c4797697e7e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:21ebb84d-caf0-59ad-a501-e8553357eb4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ccf270b8-25c1-51ed-8b66-779aecce0b6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:26325141-7077-5ae9-b228-519befc4dad1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:51c89f97-4783-5f0f-a907-324779b35dab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:400a1c3d-6cef-5daa-9ff7-c94c191c1f94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:17c8bcf1-184a-5fc4-b250-cf76eeda096d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:545e98f2-bad4-5b5d-b5ce-493f8dfc9463",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1e954a12-429c-5d6c-af67-c5b969ce1bfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a3373ec0-9979-5e46-a9f6-e8e52e695fa0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:75171f6a-d1d6-5de4-8254-b8d40068f893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eb324db4-bc6b-558d-bce9-9d50d09bb754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4a7bd2e3-2f01-593b-b35f-125d7c038b7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b5141c1e-0f79-5281-94eb-5f4b9f06d2b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:47418d2a-facc-5b6e-8500-e4894f93ae8e",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-core 5.1.20.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c846e27d-fc9b-5251-9728-f11480e69c93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fc76a41d-4a20-592e-9251-e939b92409fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4da2f26a-4d53-50e5-8ae2-c569612d1d22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:efc0c388-7264-5038-9750-8f56d5e74c5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:16af80fd-571b-5f0e-a1fb-b6988e215f87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fc401145-37db-5057-9f05-8f4b6769ab90",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e353c1b4-9c5f-5971-be16-3d4c4a0f32c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3be9b2b2-01b9-53da-b96d-c058a4cd3643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c9a65a3d-22ae-563f-9151-7b4fb0cd1d48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e33b7f91-20cd-505b-8a2f-6d43507b11b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a08822a-8d9d-5013-bc2d-c83a3c96b7ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:043b86e0-94d0-5654-8baa-f784bf4e9b2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:08c80ad9-cf22-590a-9384-fbd5029aa8b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:309c73ec-fec6-5ca4-8816-12c357a64dcb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2adefce2-0804-56db-b810-52f8d6f351c6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fb78f21e-0c0f-5c7f-8dcc-02e993349da5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:97a17d1b-9519-5a42-b742-38df8effe080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6c211e49-0966-51c5-a482-95d940065a96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2e90acb2-d5a0-54c0-9a98-34510f1944cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b4acac1a-1538-5c5d-b236-eb7248675d95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:81126b3d-3bd9-5865-a751-094bd7cda754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3439a0ff-5399-5e63-ae23-80b40866951a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eb66e8f9-e304-548f-b7f3-555a7bd21cf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ffe39876-8e84-5ba9-9806-016b4a7d739c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:427ec037-cef3-5e21-bf1d-2499c59478fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d7550f00-e88b-585a-b9bb-b662ef373132",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28000709-365e-5c37-bca4-87bddf3614c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:916f071a-1ced-554d-9549-d5850579701e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:561875d2-6aa8-5cc7-beff-9ba4f437bccd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2b776888-5719-56e8-8aa0-c99d4a04b017",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a19f99a8-9a7a-56a1-b14b-5d793254794b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b1c43058-e681-50ce-b8e3-24871ee5145b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:97db3016-70b8-5254-a177-9cecb997f122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:40b26a2b-8c05-5c14-9674-b7197c6b9c43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:80e42035-1889-5b12-85df-4825eb8c56f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c0f084e4-87cf-5708-96a8-6471d920a402",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b4e39fb1-023d-5797-87f5-6e1d3a7a6f9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3a97ed8a-84f8-55b7-8edc-a5ca13c40944",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e08487a0-a5e8-58f1-be32-374e2dcdd1df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b4eddaba-368a-53c5-9dd9-59e346a6ca4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.20.RELEASE-tuxcare.5 of org.springframework:spring-core, and is fixed in 5.1.20.RELEASE-tuxcare.6."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.5"
    }
  ]
}