{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:14bfcc72-2afd-56a0-a910-ca596994cea9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.39-tuxcare.14",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1f11fe42-734d-52ab-9039-9f96ea5bba2f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a745001b-9b66-5ac8-87e3-faeff1617b89",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-expression. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a853c7c6-4138-547f-ab46-2800c344d191",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:232a7622-016d-5770-b532-d51c14d3f270",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:521581a2-8086-5f25-8dad-3e7595cf029b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e170b0-df9a-5d44-9bbf-f1add0c7f42e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d351c8cf-26d4-52bd-b5eb-e07163757eab",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e6c5f4d-d138-5215-b305-bdffd1cc6ad0",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-expression 5.3.39-tuxcare.14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745f142d-d478-5dbe-939f-f99cc0bcf546",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a2e629d-3a53-5b90-ae49-8fa3aa56d914",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe2fa17-085b-591a-a64e-0a5dd3f45e31",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d916b180-44da-5e4f-9d69-e49a6b6fb08b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7799108-e468-5867-9931-a6ca1885daa1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f83cbf8f-7265-5ce8-8c24-2116c33d9958",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7f8e039-a204-5949-94c3-a32d582d5bf1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86de884b-a6d1-525b-9100-186158094a1f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a0fc39-cd83-5909-aeaa-0144d80a5d2d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0baac2e8-4274-5dfd-b2eb-aa45d1962cc9",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ae50e6-3da5-5dda-942d-7a52ae831dd3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-expression. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba681675-0e4b-5228-96cc-c8fbdea58019",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea27826-86ce-5039-b371-bbba144e57fe",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070ea5be-e836-5e4e-a210-e99c24dff2f3",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:431eb438-93d1-52aa-bc1f-4c2905769728",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50e7a796-7ec4-5b10-9e33-6a5c929f2085",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0b9d18-3ab9-5a09-83d2-64760ff4fdc8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3495d5d-0262-5c2b-8c54-b3606f4f31b2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16561eea-de2e-5b78-99a7-1e8a15bbd667",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e480a8f-715c-58d3-a030-e62456dbda79",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f505a39-dab7-5aee-afaa-4c8d435fd84f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6543ced-c932-5a7e-84ab-d8710f8d1a8d",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78fb2104-4465-5500-97f6-987b6cdd2336",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71579345-a600-5a28-bd2b-657ad34ef072",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc47ace8-2799-5fa2-9db6-dc520183341f",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.14 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.14"
    }
  ]
}