{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e2143f74-a0df-559c-b98d-0a55e922756c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2",
      "version": "5.2.7.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:78aa8eb1-07e8-5c13-8081-07e9566b4864",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2d6c7f2a-80fe-5ce5-9b90-8690419c9d53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8630d3d6-8117-5e91-95d2-029ee7961ef0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8591c259-282e-5ea2-9be6-60513f9a698d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b4aecf48-3b83-58ee-b1bd-8280706859bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:33d3c496-443c-5ecc-b60c-b599d63f8668",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8800099f-d657-5fc2-805a-be99e62195e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:022e5f98-9384-5adb-af12-caaeffca20e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f8c88fa4-08c4-5616-aa66-94363201cfba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:03406e9c-6909-5694-8268-ca48950f4d81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7c7ffad-48b5-5c42-a96e-cca2a0bbfb05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:db69ea74-1521-5fab-b32f-d44b2404ebbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fb8663d5-0db9-59b8-8569-d30814ff79da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:10c03da2-b441-544c-9be6-5c95f5e0fb0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:81ddaf77-90ef-5856-a164-8d2b778b30c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:293abf26-5d0e-563f-8f52-93cf9531672d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e081dd81-c912-5319-90a0-0505a0ab1d89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cbc2ad0e-d9d3-58c7-9b82-bcec74eb568f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:db260fcf-4609-542f-8e63-7024c1d9e33c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8253c7f9-a13e-53ab-8cb3-ce7eb7838bea",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:985ff737-5377-558c-b385-2859054a68b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:372bf0b4-cd84-5adc-8bc4-b7a8c1800c45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f840c04f-ea8e-56e8-8637-c99fd94b6540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:302f979e-26b3-5efb-ac1e-b1f7d25413b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ad86e04-6342-5d2d-9747-e56ce0283680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0cfdbb56-9dec-5194-b3ef-37d47ca7d8fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c5660869-5120-541a-8867-7a44997ebdc0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b9ea3362-28c3-5f16-ab45-f026d69109fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b32970ab-4ab9-57d8-8893-03bc01d8516f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e75380c3-eb92-5647-b520-aa53a5e1b5c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38dded00-f684-5643-851f-b73cd70c0be8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4e754b54-3614-5b1f-8e6a-5b20bf63d498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a66a63da-3f38-5413-b123-60df6b2f278b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fb9dac54-374a-5bef-93d3-f702500a816a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:373fc05d-b1ae-5f91-94e1-60cffbee0b2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e7b48d0-759f-51a6-a971-83674dbff97b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dceb5f7e-e177-50ff-8c19-83291802c67e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:79ada11f-8e10-5d75-bace-27e848944259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:65f20e83-cee8-566f-ad9b-a1d542bc6997",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76a0ace0-d248-5422-a21a-57b5065d034a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e7721859-e609-5c9e-961e-aa4d4045972b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d99547c6-6a75-566c-88c6-a74357e340e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:297d8f5b-2ac0-5ac8-a074-dbbd41ed8eb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d86c134-e622-5f8b-804c-77299c611f47",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5579ff57-11d9-5305-932c-266c48bfe3b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ab2c712e-82ea-5784-a871-d72425d74f85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:23318f4f-e85b-5759-a01a-41c0bac7f728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5865b782-893c-5dea-967b-3164d8babdd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:beab65af-6d39-58be-954d-d52c61abf8c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:be5d6f95-61d4-5b65-a5f6-47248b6c91ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b2292937-168f-53c7-90a2-9cdfb93845e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:019d6d38-b94f-50c5-9dfa-4ae646be2d4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38e7d628-adff-5153-85f9-6184a5bc6704",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:59d24747-6eee-5a3b-af77-0bdbeba26b79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5debd375-9d16-552f-a5c2-f12f0d87f25a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97c4f976-c892-55fe-9fb3-30c18c95fa68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ad8ab8af-673a-5dc5-8bc6-adcf5a19e640",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ed88b972-073d-57f7-a214-90728646eef6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d0938fd5-360c-545a-accc-be1bf7e05726",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.2.7.RELEASE-tuxcare.2"
    }
  ]
}