{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:545ddff0-9d98-57ac-84da-2f92926c505c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5",
      "version": "5.1.5.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d2c092a6-9dc7-5259-9135-a99489401e4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d2222631-c128-56e4-a56b-8afd7f67831d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84f009d2-b62d-5b89-a188-0add7af822ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eaff7657-2e07-53c9-9a3f-b362d8d9d157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c1722219-a040-538a-a853-45a4d50c9aa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1ae29ba8-b242-5db0-a9d1-3e01c9fe7b0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:48f48093-0d7c-5cc9-9e4a-38ee185a0032",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4c1534b3-5aa9-564f-81d4-cf215896279c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:af23f726-165c-5b6e-8f1a-ab7b08bfbcf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:78ced274-41a5-59ad-9ef7-84c45b7dc92c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7cf90345-269a-5320-a3d9-5cc14ca7c776",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d29d18b4-07b1-54f0-9e7d-b482941c3add",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:11d0f96f-0b7a-5ae8-b9ac-8096f88f6d89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a41cbe39-e107-535e-af5f-b9cdb5745263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2e9cb317-ccf0-56ab-97cd-c32bca33ce59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e6b3752e-31e0-54f7-9f4b-54905d824848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:297a9b1e-17a5-5b21-96c4-c8660e4ed685",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-expression 5.1.5.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8e06463b-0d26-5063-b280-5e7429df1575",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4333dbe5-d54f-5b03-b249-f90eeeadae58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f5cabae2-5167-5ca9-816e-1652cf555630",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f8ec1461-dcdd-57d9-9674-80949f0f56c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:488e48bc-2f73-517d-91b1-c9a2ad70f855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:119c22ac-e822-5c12-af52-2484b094786f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e19e0132-9263-501e-80d8-021b1bf222fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8959b244-a89e-58a0-bdf4-c87a06feb82f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a86ce678-28a2-5be5-b55c-794885a3a576",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:855b1d36-7fc5-5bd4-807c-50badba136e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3bee0b86-c29e-54fc-8e1a-eec558ac64f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9ac3a7e1-55c3-5466-a2b6-44c4101c8c79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:65300f46-e27c-508d-b447-210550d0c7db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e866b1f6-8117-5f00-bbac-744f9750d8b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f0b56408-f696-50d5-a350-697bc8382205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4496a700-f730-5c70-83e9-1e3d5dede99d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:39abde9e-7727-598f-8071-227c435176ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:57463aae-0b37-54c7-b105-96c1ef4afa95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f2026349-120b-5f4f-a7fd-e6ce79609e11",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d1ec9f4b-0d48-582f-81d8-f7891c5412e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:49f70a4d-516f-58ec-b161-683a0a889ee1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c42e7a13-1820-5abf-8dd4-f636e73cc56c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8d52b0cf-285e-554f-9f42-b4be9f2fcc26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e2a991e6-e473-52f1-bac1-5c0c4f2af213",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2eac47d6-5b4f-52b3-8863-4b807968af51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d733d005-aecb-5268-a972-9f99596f7697",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a1a80e2-2aaf-501e-98af-7f9027468277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:83905731-7f81-56b2-91c2-7f3d4d06e6b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ae57cfa0-b406-5521-a795-9648abe4112e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9fae138c-e5a8-5083-8314-560059c63abc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a5b06d5d-d4f9-5470-b006-9c256fbcab81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8d0799b8-a5d0-5ef0-8814-5e9ac781b127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:46618d7b-8cd9-5bdd-a659-f9c90ece9766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3234e258-5624-577b-808d-2b8006ae33de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f7417550-5bc8-5a9a-b011-3fd706702e31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e5e9e15b-8810-5cbb-948f-baf8395af220",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3fd83292-f7a1-5171-b167-fb4728e6fdf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:68a989bf-9508-5d5f-8815-51e502947e56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:954f2eb3-3851-5632-b2f3-914eadcef44d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2dab4c25-4d4e-5c15-90e9-9f067f3173d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:29d11872-b158-5895-a5e8-b6c3a553f014",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:249807b3-b616-5c0b-a208-ef840473b2bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.1.5.RELEASE-tuxcare.5"
    }
  ]
}