{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:82e3d915-8a49-5c7b-aef5-2e109650c0fa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4",
      "version": "5.2.0.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ad023907-6be3-56d3-ab8b-6d8cccd3b96a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d02768d5-7ed9-52fb-bd28-8a9e18855d2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c1d7133-0c45-545a-8a38-541b1278f183",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c845418e-85af-5ceb-8e27-5ca8f19fd102",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4bc0aa61-c5e2-5825-88ae-a5f19e7173f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ab365a3b-abac-5985-8b44-44681213414d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5b9b5e20-ec66-5566-96c9-043b197c61f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8066eb6d-3795-5a96-8aee-d4f5907a7268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c45971e1-a649-55a5-ad7c-27b27ac88d7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fa95df95-0234-5411-a464-f943e9caf60b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:95a89b87-2c81-5c88-8308-9c3f1b57b999",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f820d4b1-cb95-591f-8365-7a0e439aa482",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:176478a6-50d2-5308-bdf8-e8295a123754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a3458ae5-d18a-53f6-a913-03f2e8029f09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:887d8522-5c6b-5434-a354-92d05a83ac85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d5391443-9da0-51d1-8bc5-745b75d06fd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b26e1312-79ed-558a-b747-32e898018bd1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:53ad35aa-7320-5770-bb85-e98f489c2850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:00644baf-5800-533b-b5e3-17af353b99ac",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-core 5.2.0.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:eb199c42-be9c-50d0-bdfe-078d8b3c0f71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:01fa91f3-088e-5683-a87a-f61e24fa8bd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b0308f7d-9868-55e7-870f-ba14a638ee25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cb2c1e45-f123-5fe2-b2be-ca3d4a1a094a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e4b0f739-2f83-5e9d-8768-faab92c3b2fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cbd40404-cd38-54f0-95f0-0c4f0de8840b",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-core 5.2.0.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2037ce1b-6aad-5ce5-8f81-74de44fdfb18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2ceec238-ba2b-5a6f-848c-40fd06eb231a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5ae598db-5c48-5ed8-a9de-f61a404364e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f78e8fd8-785a-5038-b816-64fdee15cd2b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8a00b86c-833f-56cc-8fc7-a3f33ff73dbf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:03e9a0a3-cc6c-5f9e-bd82-f9972aadb41a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c15783f0-8f03-5165-a7d2-71be360952a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fe7317ae-8c0a-5124-9aac-dd3d21d8aa3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:35d21c4c-f7e7-56fc-84a8-7e62e85581d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a6f3c69b-a466-53cd-93cc-91cb6ed2d595",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:830c4872-ef9d-5528-86f9-4d5a74479eaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:330537b0-41e7-58e9-a71a-567704644f62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:26893edd-d5c2-55cd-8f5c-ad0cabbc0ddc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8ad5a822-8226-57ab-9551-f798697c9bc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:95e7f92f-c6aa-5926-8b55-d3744f1298c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:df4e23c2-9e07-5a18-b051-e37234cda5e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b85eea08-b6e9-5a59-a093-ff52c9941837",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6d63492a-7c44-5760-98d6-65fd7b0097d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a73e0769-3557-5c06-8e07-4a2d38ce07cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c5c88fee-ef0a-528b-9fb0-379199ee4803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:27e1a564-7662-5e27-bb4e-6938f7b858ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4cd08a5f-a77c-5bd4-9267-f6426218cd40",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c78b3624-f387-535f-88ef-042fbb085555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d35fd499-f435-5b0a-b91f-c92cccce4ea7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3b7db225-d957-5eb3-baf6-b03ad7212c42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:00f79918-baff-58b3-8083-913a535d2914",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:105362bb-3988-5102-a2c6-be1f63335334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b876770a-cf47-59b6-b62d-50c8f5d70557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1a4fe2ed-738e-5177-b298-258798b97cfd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:93fee88e-6c1c-5bd9-b81d-6e0567b6685d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e1edf27e-072a-5310-bcf6-a4637d419985",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6c4fed09-5857-5ac2-aa71-5abb7f143472",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d001ff5c-511d-5835-8479-1c6cc43e17c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:28e8521b-585e-5f6d-9d4e-78d0ba891753",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6ab2cf22-58ea-5518-a48f-35b4b4ed5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.0.RELEASE-tuxcare.4 of org.springframework:spring-core, and is fixed in 5.2.0.RELEASE-tuxcare.6."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.2.0.RELEASE-tuxcare.4"
    }
  ]
}