{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bc7a7068-a567-54e3-adc0-343229035ecd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6",
      "version": "5.1.20.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:46a3bba9-20a9-577b-882a-1bec51a73a78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f490c951-9dae-54c3-bb36-5261062dbaab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:13b65a47-16e6-594a-b91f-3bfefa0ee61d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1220fc06-c045-59ba-900c-7e6330a09adc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f96342de-75b8-5f4a-862c-08a7bb519027",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5a129415-8fd5-5201-88ec-4c4f06d6c346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d2992492-9efc-570b-9c3f-fa41903b3efa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5db89a9d-0d9e-5e6a-8a7c-8b79a29429e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:47ef2fd6-e682-55b1-bb53-a093454fe16a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d14b6daa-0d17-5e73-bd96-9b0af8af6ef5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a162c7f0-b3ed-5c04-acf0-1ab3dd6dda61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3d8dca80-29fb-5b1c-a023-cf67622cada8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e16e3ffa-d0f6-514f-b8f6-597163a713e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7457dc8e-7fa1-51e3-94db-0d790d7fab17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ad3fa9fd-3141-5b8d-9df1-07790df95280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:58f05881-7020-55bf-beb4-8ff52c1ea9d9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-core 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:19d8553c-a119-5f65-9f5d-5f58794937b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:997c771c-1f28-5f91-b61f-54ebd077f639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6bb2bb91-2119-5a43-8e47-9f31a80e4ad4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:90398b25-7548-542e-83b5-f205b60d0c75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a11b47e5-7570-511a-818c-426917821439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1524d366-68ec-5346-9e49-a7edf0827aac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:862602ec-3355-5d49-b294-37e88166017c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b77495f7-4c7a-5081-abb1-e820c761cdd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9f1a7f6c-d89e-5776-ba23-6eaf21b92aa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ab6b390f-2675-58ea-8996-533358987b4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b539e213-33d6-5aea-91d7-392a6649280a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:53e8977b-716a-596b-b766-b5210d0c9494",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b06027c-12d0-5eff-b309-8afa2c536c25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6ff4205b-bf2b-57b5-9910-8155eecb4b2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cb17edd6-2e8b-58ff-b472-611719077d61",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9333419-e729-521b-9c64-c7fd8b398db6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:95f002be-5dfa-56e4-b33a-bfb192d5e14f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1efd5a1d-590c-59a8-aba5-61df8064432c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:255a7800-2e80-5302-9b9f-3992cb2ad306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:25f3c51b-2ae7-563e-9858-c7595fd5fe43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bc9ba5a-f39f-5632-9740-3a839f649b8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8205243e-e31b-5fbf-a5ca-1a13e6b746fb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e9a4cf55-0a25-5a0d-b8a0-c056c451841a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1ac78e13-e325-55a6-b5f4-c5bebb443c7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bdca7ba5-136c-57a0-9bdc-3bb24fd38fd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:35134d40-9112-5c05-98cf-aa541bd8a706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ba06af5e-5dfc-56d2-a3dd-d15dbb7e3059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:afac90e9-e47e-51a8-a877-f8a06a7d6339",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ed381f3c-076a-53c9-bb19-886d0e661cda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:074aaa88-a890-5201-96be-8cbadb7cb56e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ea24950f-5893-573d-8002-7c07ab864a90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:669ea898-c491-515c-892f-e14e312e43ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f1714e8-775f-5856-8ab4-e2866199ae98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c76fa96c-6ab6-536d-a6c7-7fa5288077ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a766d825-7a2f-5937-a628-b23d05da6cca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe5fbec2-bfa8-5578-a210-76d8b0627d81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:84794502-3d23-5785-88c8-e9d4909de4b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c42ced0d-327b-53ad-824d-6f8b25f072bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6257a000-52d8-5249-8673-fb1a4dd49305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b5888063-04e0-5330-9815-2c956f86d4e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.1.20.RELEASE-tuxcare.6"
    }
  ]
}