{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6cb19a1e-4f3f-5a38-8827-4d947dc4127e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "4.2.9.RELEASE-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:247407e1-42ae-59c8-940a-55476a5d146c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556b8779-7db1-5bbd-bf70-c28931b4a0e6",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:647c4637-7662-5322-9558-581faab79a12",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0f108c8-5a99-5903-b9db-f1c652f85e2c",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb01016-884a-526a-ad20-56e9c423372e",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22ddb317-fdbe-5dd3-9ea5-1dfaa76a1007",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20cef8f6-e112-5544-9a3e-3a2768e41865",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:953833b1-28a6-5287-9e4c-014f3f25eea1",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2714c00a-9ff3-5b37-a8e8-d6b17a1269f2",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82cfcf55-5ec8-595f-b090-db365650c220",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21b0641e-ee5b-5869-a675-f081661cf5f9",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ead025-6f80-541d-99e2-3ff164a518f4",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b47224f-1704-50ef-918a-89f06f9bf37c",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2c00ac-c6da-5709-b53b-9cc392e719e5",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82537e58-1957-57b3-9e2c-65941c6c7580",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19e7456f-461a-5a7c-ac56-b3c4ffcc7ad8",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c557a77-002b-5972-9edc-6050a48a69e6",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abfb664f-88b0-5842-940d-a343c6d9daf1",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03702f51-4557-5d76-94ba-b273a496ac21",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d988289-76cb-5090-9e8d-a7c539ca39ac",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7168b6ba-e4ce-5618-9a34-15928b86b1d7",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc40ecdd-5b0f-5728-bf47-e6010f52cf7a",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ba2a268-a90f-5f56-b553-a74475545513",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:030aaaed-0ae0-56a6-a301-2495674eabd0",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:388fd3a1-0eb5-5767-8431-ef945fd772b1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63d5b79-1c8b-5bda-b987-5f6e2c680f1c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:169e9cc6-9759-50e8-82fa-cb57cd12dd8c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b973d2c-981b-5e0f-bdb6-cee9cff68b4d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aee90e7-e1b3-5116-9a2b-e11047f4073d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b19a95a-95e4-57c3-8dd3-3d58a48803ff",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435681a2-9653-54f4-ac51-07469e00bebe",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fad445e-854f-5585-be26-7d5c29e1f5f4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d95a62c3-ea28-596c-9d15-b3ec2539a722",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94dda8a9-4e32-571a-909d-c6b01f205d89",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32519faf-cd4b-5fae-ba9d-9745b8b5400c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f694b9de-f0c7-5c7e-8f08-35c1e8d6e304",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4ff9f1-47d3-5de5-af72-807ad283dab0",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:735cff5e-5c09-518f-bd52-ff470f7da8a0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:076f9ec3-f252-5601-a2a1-a2143238533a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2cdf1a3-eb48-5be8-a36b-1062aec1539f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcbcf7e1-51de-52e4-80d8-3df479e78fcf",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e97d41de-7c9a-55c1-9f3b-8565c01ffeae",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23dba3ae-6e0a-5789-b530-f2c1a52f4003",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:396ff7d1-dc08-5e4e-ae63-8b05179df51e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c926991a-8907-548e-a5f5-38e6ad282c60",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0f73fdd-f20b-5715-8dbf-c1ac9eac3223",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74975e5b-84d5-5cc3-be21-b9da0386fb18",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.8"
    }
  ]
}