{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6b36f1a5-a462-59d7-9a37-af8ae2141a2f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "6.0.23-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:702ae034-981c-5fa5-9267-4b58ef58760b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b970ca-28b1-540c-939b-c406526831f7",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce9ea9a9-0046-5aed-a451-f434c7a27acd",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25715076-deb3-55c6-b070-b55a4de6ca3e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:958d5692-68a1-58d0-97e1-f68a4b0f7a53",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d8bde15-8a79-5ba2-85ee-6c44a6d399a0",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5f6b03-459d-5b64-83f3-b3d4161b19f9",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:924f3cf5-7ecd-5ecb-8442-4f0a4ff52b68",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2b117bc-9792-5a97-a1fa-c9b67b8f87de",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb469eee-5a6b-5171-b92c-394ea1f590b4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cd03a29-59b5-5fc0-8695-4aea9a4a7e40",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0af9564e-f21f-5c28-803d-e95bdb71988c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:145c3d5f-d55f-5cf0-b18d-69cbdb011c52",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f0f966b-25ce-5e65-a441-99ffab1b4330",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a27062d-363b-5287-b785-66d0ed4b0f46",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb4af80-c97e-557d-a2f2-397f68cc9e96",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87cf791c-7af0-5412-8e4e-7dc115d36dab",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20ab1921-492b-5990-aa76-969d0c5f1028",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e211a936-65f2-589e-b0c9-968a90f3f7bf",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a84acb-b568-58e0-9e4c-181da9ecce93",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dccf85bf-4ed9-5bbc-8317-bbb6bcd72bb9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:317c9a17-64fe-5565-b42c-0af72135bd3d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcc640a-a395-582f-ab77-06ea089b310d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29b44c8-0ced-542c-9930-16504b58f218",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:534f815e-f338-577e-a3fc-d49e019377ee",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:290c76a4-c307-52d4-9e74-b3f5cf2afd46",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef627a0-ee34-5109-afa5-bae1787b5372",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd1132e4-7bbf-5c6a-86f5-f442fadc4821",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.23-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@6.0.23-tuxcare.5"
    }
  ]
}