{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5eceaa75-b227-5bd8-be13-c08db64098a3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.24-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4ed06aa6-7b22-5dbf-8e00-c5df998eb2d5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f9b455-37cc-5f3b-b7ff-f8ad9e71fd9f",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad9aef86-60f1-56ff-b7c9-6b04b295b20d",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78831c7a-7037-5f75-b0e9-304fb1fcfcc0",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38340407-5cc4-5790-ac68-2775f30a4204",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1887f504-236a-5ca5-8d5d-ba43bf2e4863",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f95807-bb20-5323-8ccd-407185ddc5df",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c61caf3a-46c8-51b5-bdec-8927a85db624",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37fa5b7a-b098-5d82-b4e2-3342a3816715",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aded085d-255e-5294-94e0-ba4b0601e2ca",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:421fdc4d-72e9-5ac4-b78a-2b3e84d56e85",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc31a923-b7ee-5d89-a7fc-86a103ed7d8c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5585a1cc-2756-5e47-a0c9-413a12cb0c96",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427319de-925d-52bc-98c2-144d62846854",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d96692-f6cc-54ab-a1da-3da40d6e198a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fa45534-2d85-509f-8f07-78419efb9199",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac3ac4a0-2e39-586a-92b4-baafbef9e326",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c1611e-8421-5b72-ae5e-1a08aa6dfb6d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27595227-54b6-5d51-a30f-2b7f43494fb9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba644f24-96e9-5c5a-b658-a8c6bf19c1b6",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2a6028b-547c-53ef-bcfb-ea29c112c832",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c3fab62-89fd-5953-a973-d06c79a205a7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb774d43-150f-5db8-a3ef-2a340ce65b63",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b1c149-7ad9-5943-9a48-db70e2247d42",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d48c9036-e633-5ee7-bd3a-2356762b9f07",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.3 of org.springframework:spring-expression. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:399bbc4e-d977-5933-b3ca-1e1faf4956d5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ec43d1d-eb07-503d-ba7c-8ffdbb88c675",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e663ee1c-3c25-50da-866f-cc1eb67968bb",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53d47f39-cfbf-5533-9826-84a56d97f123",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1449382-347b-5cc8-8de9-98b0f2d3fc2b",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6a216e0-1aeb-5f0b-a96b-ecd216dc4e76",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f713a8-87e7-574b-8950-ab81f1a8efbe",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24713fb2-10e3-5bb3-bc2b-0b31c5c63722",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51659f4d-41af-5cc4-8986-c1063eb67b40",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72cc9686-bcbe-5603-9c7a-4619d9d0f355",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:182026f8-b6ce-522d-9f05-4e1460785b59",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff873fb-b15a-515a-ae78-89d580041d4c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17cfee3b-b09e-5dc9-89ce-323a67afcfdd",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81f604e6-3b1c-5ed9-a134-580d8ac937a6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.24-tuxcare.3 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.24-tuxcare.3"
    }
  ]
}