{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4eae9d58-d567-5037-a968-abd00494fe6a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1",
      "version": "5.2.7.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f57af642-63c8-51ad-92f5-89d21ae1e4b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae3e24b8-65a4-553c-8858-3b5df9e4c35e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:704b54c7-1437-5a3f-a2ac-edebf13a5abf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02232e02-d24d-561a-96df-6a92b8b76407",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7da4b9e5-b5aa-51a8-88c8-d29b9f828972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b5e9fe21-543d-5ab9-adc9-5754618bdf12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e935f89-40ec-5c43-8925-9a1c7d1eb6fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36e146cd-4a21-57e1-8eab-c636096d861c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4efc92e8-e58b-51c1-88d0-3b62e78c31fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9623233-aa0d-5720-b313-06aa20d56e5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f925367-30a9-518a-9c67-172660c659b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:14ede228-1832-5f30-a56c-48cf9b62d8f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4bef7c97-0223-537f-9f04-348b684a086d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99b853b0-02b1-51f8-b2b5-47615861f560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ee33652-296a-5798-ba7c-3055d30835c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:288cae18-228c-56ad-abd3-4bd0500a46c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d4c80ce-eb54-5cca-82bd-73fc098cbe37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44ecdfc7-dc99-55ca-bdc7-f21388171ea1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9d363bc6-6950-5cc3-bcdf-65a0187df3a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30de5207-147a-5f86-afdd-35ccaf2c8cc8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a971e068-9096-5e9f-ad31-24f6d44f42dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86be3159-c311-53c7-8329-89418a200df3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5beebe8f-bd5b-52f9-885d-1762e6c93b5b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a395474-7f4c-5193-b9cb-25dc7c59c3bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fca85820-0ce7-5f8a-951c-fc2afa7426c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e4b86fa-22b9-5f2e-823a-c55f5fa73a22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:197ab6ee-1c7a-5a89-b237-17b545270812",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:993d50b7-26a7-5f05-b4c0-07edeafadcc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b35cc60-3cbe-529a-ae26-220fdfd756a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de2afc93-5ba7-52ac-93a3-69809d2d1a4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b7c21d3-8ea8-5dda-966a-31a3411c4856",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15e14467-aa42-578e-93c7-b95de971b2ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f0835f17-3149-5966-ad08-0b6ed6899742",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:84fa546a-d537-5a74-82f4-0f92cba19526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1fd24e5a-e365-50db-b95a-1f3c2fdba91a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:04322e46-081e-5e5c-b4dd-4f72cc1f1b5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:662dcb40-da21-57fd-8963-57a9c5f0247e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40f0d637-43ff-5629-9848-fc5c7f9bddd8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65c92641-9c6f-5448-81de-0c8569119481",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75f5bb23-cb9b-5c32-bc0b-f4634fda83e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d165b48-55fd-527c-a375-8a5024b16600",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5c7b96dc-cf1a-57d0-bc51-f749176d630f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:209093a8-0f61-5e81-8e60-fa124b1dc8f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ffb0d519-da6a-5d39-9118-db4a9cf3572f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a839dd02-1958-5abc-a3bc-5ced6cba36fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec7407e0-2df6-541d-b29d-de52bbe123c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7dc31a30-48de-5039-ac20-a97d172b8b32",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a82b0b4-2286-5281-a5d6-26f208e5ec90",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27ff9ade-e2aa-52e8-b675-472bd8473b61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae57e198-a3fc-52ba-a12c-bd0ff47546d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d89fb13-2ad9-584c-97bc-136f228bf19e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53ff5e99-a4a2-5ded-8163-339dc9b80446",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55b44b8b-bfe4-568b-9c26-8b551f1c4d03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:efb6fcc0-4f53-5cd3-8460-fa12c906d8e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f63008f4-8bee-5c32-86bd-eb2bfadb0c59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b05e34bc-580e-50fa-9401-243759ad7500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d4315a8-b53a-554d-a7d3-7a57fad3fe22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d222d7ae-f3d0-5e06-8bbf-863f2f09c426",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8b62427-40ce-5d60-8014-810492135141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.2.7.RELEASE-tuxcare.2."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.2.7.RELEASE-tuxcare.1"
    }
  ]
}