{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9603922d-047b-58c8-aa46-ed2e052156d1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1",
      "version": "5.1.8.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5f575858-b172-5972-b47e-f52e16ed15ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9fbeff02-9849-5381-8b7e-aec99a94a11a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5398 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:036e85f3-e9a5-57c5-bfb3-05128a6d7656",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87a7512f-1482-5604-8932-ae96276fd1ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b320af04-ace4-57f3-9172-56355218dbb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1eb0ac57-b275-52b9-b4f3-69105be2ab42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85e8da8b-b205-5dcc-8c29-c26e25f8454a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b2fb7a27-431f-5ab7-a927-f22534873e19",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e593ee38-e953-5ca0-82c3-50ee85952d79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2380c527-002a-53f9-8de7-26ec8ea19379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7fec5abd-a72f-5edc-8f40-e2bbbe292923",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3583480c-8acb-5ecf-8f64-7303aca31776",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d7c7b6e7-553e-5fd6-a6ab-1b054e2575a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d07e2419-5945-5b72-8d41-2d709778d3b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b37f8c0f-defc-5ca3-81a5-6145f94ab8cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c1f723a-c5f2-5043-a1a5-0b9ab17a08e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b918f62-2d5b-5fc8-ba46-193f7cdf01bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50d6fdad-16b7-5f6f-8303-8ccf9f71ff3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:96e08ced-4938-568c-aadc-3df02cb5399a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1263e4f1-07be-5fff-9978-8740d457b038",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 CVE-2024-38820 is not present in Spring Framework 5.1.8.RELEASE. This CVE fixes a locale-dependent vulnerability in the CVE-2022-22968 fix, which introduced case-insensitive disallowedFields matching using String.toLowerCase(). The target version predates the CVE-2022-22968 fix and does not perform any case conversion in DataBinder's setDisallowedFields() or isAllowed() methods. The vulnerable ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d816ce16-440d-521d-9aab-69dd86de71dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52e52865-17ec-583d-b57c-77342068f835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4a3c8ec-fb5a-51b2-8e8b-ef40b4e67ec4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:df094334-f528-5281-8153-609adf7cec43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71324e13-4a8a-5834-ac16-163c985495c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20c0fed1-193b-5e03-8232-f50e20aeaf49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d724a10-b2ca-544c-850b-0af24af6ff58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8dc623d9-ee88-5d78-bd51-3216bbde2618",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f45bde1-b173-5558-a5fe-671cfa9c1eb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b46a195-1197-5e94-8552-be1251fb4965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16bdd0ae-af95-59f5-9bbe-ee2e9279a90c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e598ce38-1dda-5e74-915f-5781533777e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:00b1be84-4591-5710-933f-dfe82a7bc69f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f667b268-072d-562b-8fb3-6dba08b5db0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f300f4eb-8556-5b1d-9468-2f221c9fa09b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cbf246ac-7df2-59bb-921f-88b5f5582ef9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9c393749-7c15-57f7-babc-d780fe0919dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a04ed9a-4da3-50cb-a28a-6b2f77a4136e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0fa11751-c993-53d1-b1f3-002fcd196908",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 Spring Framework version 5.1.8.RELEASE is not affected by CVE-2026-41847. The vulnerable `filter` function in the Kotlin Router DSL was introduced in version 5.2.0.RELEASE (September 2019), which is after v5.1.8.RELEASE (June 2019) was released. Version 5.1.8.RELEASE does not contain the Kotlin Router DSL filter function that has the lambda parameter shadowing bug described in the CVE.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:649a853e-fa61-54a6-b4ef-1635466b42e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6404008a-e542-586a-ad85-fce746cbcf77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:05f13546-6ee6-500f-84f2-ea6401603c7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c217557-c39d-5d91-9e50-bbd9e97023ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2f9a50d-bed1-5e42-ad4e-aca7ea80eabc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aeece156-5ace-58f0-aab5-89bec4725cb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02996366-677b-561f-8784-9f095ae9b812",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:112b1fae-8d65-581a-a2cd-1f1df66b7ec3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5faf7194-f4fc-51ed-bb99-9e79d2523916",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18363af2-4abb-50ef-a9f0-c482ddc188b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2a56858-e912-5903-b67f-294cd735ab9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ecebcd7-82f7-52b7-8141-47bad5fbffb4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47891 does not affect version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 Version 5.1.8.RELEASE is not affected by CVE-2026-47891. The vulnerability describes incorrect enforcement of the maxInMemorySize limit during Aalto XML async parsing. However, the maxInMemorySize feature for XML codecs was not introduced until version 5.1.11.RELEASE (October 28, 2019), approximately 4.5 months after the 5.1.8.RELEASE release (June 13, 2019). Since the feature does not exist in...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ee8b0da-5a09-505b-8367-b203c2cecd33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a3e74cd1-6d86-5db1-94d0-483247802f16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e368c8a-950c-5d14-b14c-18d4e162aacf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e53a3d3-1117-59a7-b636-98bd2b1d5b5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4c9526d-8e8e-511c-a50b-638a812671cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1c79e634-1f44-5faa-9e22-6435b0a8b33d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.8.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.1.8.RELEASE-tuxcare.1"
    }
  ]
}