{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5e3bb198-b793-5ca7-8966-02919a6d592e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6",
      "version": "5.2.0.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fac39b85-cc7f-501c-8ffe-252acf1f9620",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ebc5cb8b-0e4c-55af-96d8-d9d18b065811",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e8d4cf02-2c58-52f0-bbd6-47ff351e219f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5fdb3418-245a-5916-9e5e-2009ea655f5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6883126b-67a0-5645-b0ea-caeddff02ee0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c753cf66-fbc9-5139-9943-73801be14fa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ed226621-57e8-52c0-895f-9077e0bda990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:061a57c5-1b3f-52e1-8a95-48a9b3ed6be8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7665e589-ab2b-5589-a0d5-a30dce2e325e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:00e487b8-2c66-522f-8a57-8362870ac876",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e991b0a1-c52c-5e1c-8f42-c87f13969e7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d69cec47-1673-501a-9435-f49d4674d7ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bb0f15e-3a54-515e-9041-21468b7f91ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aaecaa95-b016-512d-b48a-5a5ebf40d14a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3cc3013f-9c4d-5d75-82db-b9be63380f10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:445baa60-8de3-5e66-8dba-866339decdad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8cc93502-cc66-5d06-8416-057b2bee5f93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:53192340-e76a-54ec-ac06-d73b53510249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9e49f3df-ff62-5aec-a102-1b1c0a8929d1",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-expression 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e6085457-d0d2-57fa-8a31-be4b3e1b8a97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:41bc4209-684b-5744-a80c-4e61c787ed84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:faa25d2e-ec94-5f1c-ada6-2278bdfa6eba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3c200a44-ce62-51a6-b321-11d7a572b0a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d68c1985-aa97-5307-a198-51ea86a0329b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b8d367c0-60de-5483-a62b-84beff6b1e30",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-expression 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b6831f5e-e2ac-5306-b627-0bfd12606c2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c128eeeb-cc8d-5367-9d07-31f0e565e186",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8cc510e2-1067-561b-b80d-955083e37736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:953a4502-4230-5b78-9422-2af677b4acac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bb12df2-6dfb-5dd2-86a0-6a0e4425767e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a3ab8cf8-729e-52e0-8a32-399a8f3f9bd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:61f10439-fdb0-5a42-97f8-55153c321683",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:18e6b2be-9927-5eec-9c75-7d4f3339d171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b933e53d-1eed-5cba-8388-d40ecce423f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d9f89246-3b20-59fe-a597-c71bbf15d961",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:37d0720c-2f9b-5699-91fa-f7dc8aae1690",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1af4559e-90f4-5542-b367-b67960eed0fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dc83ae62-1cf7-53a4-9347-f06486963c34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:104842cd-9b57-5827-b4d9-28b31fecf205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7373675a-1daf-5538-bfc1-e2eb91731c85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ddf8529b-7199-5dc6-8334-a4ccf9c8b2b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:43f9d92f-56ef-53b9-9928-ad6b9e05ac8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0fda81ae-2255-5cb5-ba3f-68741161a027",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4ffa4ab6-8836-555a-ae58-8ce212c9ffaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:508ac023-d3bf-5565-b9f3-c9c754a54f46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:377d5ac9-c319-53b2-9230-1037f3b52d19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f2e3d53-35ca-57cf-8462-91486183cee2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2a4d2e7f-afb5-55a7-ad30-6502fa27b3d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:82f53735-6531-5f3d-8ee1-304731aae5c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:973dc601-4f7a-5959-bbe2-4f0dd7fab147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fca1eafb-bf49-5ae9-85e7-6a84465115ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:31959894-cac1-59c5-94f9-532299324bb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1560f618-17cc-510d-9040-229a07b1f593",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:68135593-dfc7-50ff-a884-ce840ec7f16e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:16e5c50c-9238-5661-83d7-bf882831fc52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:93eb02b3-0990-537c-8a05-4f86db386235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8d3f51e0-cbf4-5b19-a032-84b6590e1781",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:66d45bb7-7466-53bb-8426-316f26fdd74e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:652f0f17-1f22-54ec-aaf5-c693932fdaa7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:07a14d1c-4aeb-51a3-8681-5abcf43f5234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.2.0.RELEASE-tuxcare.6"
    }
  ]
}