{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:740a0a51-c884-5be3-9270-9ecdba9d6d56",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2",
      "version": "5.3.33-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:73eb143d-29da-5790-b9fc-d001a239849c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9baf936c-140c-5e5d-8929-cdc35aa000d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32d8c57a-efd2-5b5f-8a0e-f741333be5c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:34c9d180-6e87-5fec-82a2-4ae6b08aa8b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:49aa1064-c3fa-5a02-b5f2-cfb60ddabd65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45bc0b9c-3acb-5c4a-a2ba-c1a1892f162d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d4c9d60f-c466-5348-b325-5ae2b3d0634b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7c36dc4a-30c7-50bf-ac2e-16575f8522f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:659c680c-3b22-5560-b3d9-ba6beff30a78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:500c44f5-7bef-5b3b-8fa9-089306ed3c71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:046ca2cc-b353-5720-887d-f19eb5dfee70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76db2a11-80e5-5a38-bc52-1a98bd9d79b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e94fa3b4-2d71-5a02-bec9-54f26b557d7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e50323f-6a65-5a61-bc58-87d8ead9f452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f6c26404-909a-517a-9768-46a32506be5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0d9acef6-b5f2-5bcf-a8f9-e7a59eb7693d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:776103a6-1816-533e-982d-f5afa0de4f4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bf26cfbc-0682-5a9e-9bcb-24c0fc352fb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ba4a53aa-3e46-5022-9f21-86d6c64661cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d0d550e9-e867-5a4b-bce5-36ff45a1a1dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d6bbd635-0ad7-53d4-a89b-ff8ba62a07b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3f07c8e4-fbf3-5d78-b71a-7a4e6118a9f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:75aa4f8d-f58e-5060-8432-1af585439bff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a03234c1-f069-50c6-b4e0-85cbe1b39399",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d0e0ced-8cd6-5328-9cb3-1763a1060d89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ef23876b-f149-5f19-9ee0-334ec2489a53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5ac95c39-70da-5393-8e13-d883422abad5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:acc6f4f5-deff-5246-9440-efe93032534e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:750d7423-6b4d-5678-af8b-2bed823aff29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8158a546-6e83-5247-ae05-95c79fdfd19f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5d6ab6e-8cb6-5cec-9b65-9bd9a6fc9d1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f43fd298-1976-577e-bf22-22e3c4d69c23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:79a436d7-7984-5a90-b324-6422aa7e4bd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ae7bba0c-5365-5cd3-8c30-a174d19c5448",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:868a206c-db9a-580a-bb7a-d61ddfb7a7e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de276448-e857-5dfb-b5a7-91742b729630",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:39cadae6-d1e6-518e-b0a0-741b802e9638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:277b20f7-ce4c-5a7a-80ff-890742411846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e29913d-a09b-57fc-984a-e5344e5fce86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3cd767c8-f3ec-5bae-8d41-a05b355fe1e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cf4c83cb-d572-586c-88cd-7621f40c4c24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:778b1941-d066-562d-928a-83791264cde0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b26a1c69-f991-5a01-9d32-c8477168c143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0b706397-0746-52da-a0bf-fcdf3e8bd527",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1de39ea3-3f1b-5ef8-9ee3-5381a6ae10a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cb4ec108-25cb-55cc-8165-836e68534146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:242a65bf-181b-5aa3-9b28-f348564dbfab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76da945a-b13f-53eb-ac91-15e40f275193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.33-tuxcare.2"
    }
  ]
}