{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e6028ee9-2669-56b2-b3cc-a61042494e0a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5",
      "version": "5.1.5.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3edef426-c9bd-5d55-b76f-ea19060f1c52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:19e026ee-b72d-5ba1-8a45-7026ac3e04ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d3b96f5-bc4b-56f9-a944-987927e8815e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c1b2ef4-80ce-55a6-93a9-01c577767bb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:99710607-56e2-5623-b244-236c07175e10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:448fdf7c-afb0-57a7-b1b3-98de6a980ae7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c0a661ef-8f06-5b3d-b133-3e3fe9f034f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9baf718e-6f2e-5651-804c-d47aaaeafb83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9dcf4ec4-844c-5f33-b26e-f56afb702068",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bf2dfe05-5d2e-53a7-b48e-9b5b60fa0429",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1173149b-67b9-5825-8f19-7742f9963c56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:89f40f86-5ac9-5166-bc65-83ebc81306ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f0193755-c0c0-5a2b-8c8a-da044c919d6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b9be0503-5071-55be-85a1-f3c1f85a9880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84b6f6de-70fb-5c4a-b87b-0b150c8cc68b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a20ec4cf-857c-544f-b1c7-539522c19aad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fc2c7532-0caa-5265-abe4-c1998f488f83",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-core 5.1.5.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f9687195-6ff3-5a4f-a4b7-228dfd8c0cd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5d34261b-31cf-5dfd-b3c7-3cda67fcafe3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d2517c6-981f-5238-9b93-eb33a21e1574",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:00f88d82-b64b-5d0f-9ea3-71674776e586",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d64fc2fd-4934-507c-b90f-76a827b3f99f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0690cd08-859a-5caa-8a28-7534f4a1e3f9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:149ba3ee-6e96-5bb3-9128-298ea72a5532",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:64a6ae8c-1bc2-54fb-afc0-5a8595675419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aa2fdfcf-8874-50fb-9064-2e4839952f4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6a8575af-134b-597e-b204-21e647b2ce69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b7de733d-fd63-59aa-ad23-b81558a45dd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9e8e9797-fcd3-5477-acbc-5443eb490aa2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d742113a-4c06-500a-b8a8-9cd0b3bfb122",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1b10aba5-b95d-5c9d-b7ab-b28332634f4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9182583a-2e89-57cf-be6b-5d87f78a0d77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e98789c-a143-5e54-8845-9e52c3cfe63a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6158d7d4-a72a-544e-9c86-018a252cb69b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:15a41273-92b9-5c04-ba62-b90e935f8b0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c322a74c-4a70-5834-9590-bede517b75dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7b7242c8-777e-589c-a3d6-affdaa7d40a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d3ff21e0-1c62-5f25-9d5c-e136fac5cd9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7b7955a6-a926-54a8-98ff-da189d53283b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b6703469-831f-5c55-b2ac-47cab7185ff1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:99bf277c-6464-5455-9cbf-0e3a6f4a35d0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:98b7ef39-117e-56ea-bb23-4279969d823f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:29ee9862-127b-5ac4-8793-e760f0a363dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f12ef706-46dd-55c1-9f4f-317b7d7bff02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d86da7c8-e53b-58b6-8612-77be2cca774d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6d296945-3a33-5149-afe9-a090e002f219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:267ba877-bf2e-5ae9-8174-3871c8fab311",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4d870e9b-a0a8-5ac7-a8e9-61bfa6f7f78a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4af30c69-c297-54da-a053-af17ca6517ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c1d93acd-ccb7-53f0-b65d-1671104daaa3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c3348bf-8894-5cc3-93d1-1ec864b21384",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c1f9344-dcd8-5d96-96f4-44654b0e53cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:07ee0d51-621c-52f7-b5ee-3f02a05a468c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:63db35cf-f4b9-5592-b137-c9347c3a4e2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f7d7cd9a-78e8-5b02-b961-8e3ad74038cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d1d2901c-8def-5a69-9331-23437ec111e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5a19e9a0-3bfd-5d57-8d4a-8bf766561e0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ebf455e7-4c76-57ff-88c0-dde1de9b9faa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:40a020c2-1996-53c4-91b4-fc2b3faf43a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.1.5.RELEASE-tuxcare.5"
    }
  ]
}