{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:898e5067-4218-5348-8f6f-ecaec9cea618",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6",
      "version": "5.1.20.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e7023501-eab3-5c2a-8391-a19c9a04c7e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f4317a03-708c-588e-99b0-62bd9f519b62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7681c813-e1a2-5b77-9a6c-3d4a725e0ec4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d1681ebe-9dee-5dc4-bf3c-fc7dc942f59c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3a13b96a-1de8-579e-af2a-3534c3f2aa57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6cf87f56-b2b0-561b-8d39-7b0b3edd6054",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:247903c7-fea0-52e5-8d6b-d83c852a91c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:faf0081d-b7b5-5c04-8e2b-4bae32ee01a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fc96e6c7-5089-5924-9bdf-019977540732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5d7508ce-1470-5107-9218-528c322c3624",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4cf15203-3122-52d9-a57f-ff3196590b97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:660555cf-6469-505b-9c50-889f9b7e957a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4039802d-0078-5170-a8ec-4daa32466200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7d45f974-5df7-5155-a681-06fac04d1e10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:38216456-9100-52ab-910c-dd9694db3b8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2c544808-ba09-5702-ba22-505453f90492",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webmvc 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:80e3125a-117d-5672-a6a4-42d6c3830478",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b927641e-e320-55f2-af21-eb6bb4fe356f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5e273aa3-3dff-5d32-808e-6b39ef99054a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3a4ace60-6e7f-522b-90df-e3bfb3567edf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1fe1b337-e5c6-5ded-b360-7e246ec3a2d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:039d9e40-d66d-5ef6-b595-00591d7d9eda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6d9fed4d-4b52-5c33-b13a-69efeaf8bfa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c01c6feb-cfe9-576e-bb35-db74cbebdd83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c2b1c97d-12de-5a97-b88a-2274003a8c94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:939d3f0b-f492-577b-b247-ccd03f353a9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3379a30f-6522-5d5d-9b43-b291f5afc8af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6c705020-442a-5dcc-a196-2101899ea4c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:719f15aa-8d64-542d-be11-d9f16729cb92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cc1ef51d-faac-55bf-9728-b9eaf8257825",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:83b72e7a-31a3-5932-b032-39f80ce7eb35",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6069b644-d9d7-50a7-9561-6549d801c247",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:713d6390-4060-5f33-beb8-d33f16d7600e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:50e5ae1d-4510-5215-9f8a-20fff2265317",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b21760a9-0c7e-5e18-b1ea-a413ffb678e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8f3bfb33-6ce0-58cf-a6b0-6efc46a9402a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b8b6b3cc-347a-53c0-8069-8b14ab01dc20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ae3f8b9f-77df-56ec-b7b3-01348b89ef0f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:742ee90a-a56e-5f88-8131-461f5ae2bf5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c4d368fd-ce4d-57ab-938e-b261e7896e2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cee4d553-81f5-517e-8a37-69543cd61fa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:10a25e48-d780-5dd5-804e-d901345f1964",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:162d5b6f-ec8e-559f-9f75-ae9adc4a090a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2ec418dd-7ebc-528e-be5e-f9bb6e642604",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1e980f72-43f0-5278-8058-ea0fb13d8df4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:37434e82-85da-5498-8558-171009cf94f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7166eb6a-c050-52b9-ba04-5015d623823c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7121ca37-2e24-55db-bc9f-4ab0a07358e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fa0d1ba5-f630-5184-b8f4-d24789ead2f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f71526e5-d5b4-5434-acc1-8bfb620da3bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:955b1e0f-3e2b-58d1-83e3-5d59e4c683a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:87b9d432-071d-52de-a8cb-cbde3b9df98a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b3731f59-ac54-537d-956c-9ac7d070aa09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:84ad358e-c1d4-562a-890c-4fde29b4d0c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e2894070-45dc-5b51-ba10-47b175bb2baf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cca8cda6-e726-596d-a7ce-3ed66c9e2cd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.20.RELEASE-tuxcare.6"
    }
  ]
}