{
  "@id": "urn:uuid:288dd989-8de9-45a0-b6d4-6ee2c082c7b0",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2007-1651 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. not_affected \u2014 Target = Spring Security 5.8.15.tuxcare.1. The OpenID module and OpenID4JavaConsumer.java exist, so the vulnerable component is present in this project. However, the upstream fix for the CVE-2007-1651 / commit f5468087 issue is already applied: OpenID4JavaConsumer.endConsumption() clears the cached DiscoveryInformation from the HTTP session at line 136 (`request.getSession().removeAttribute(DISCOVERY_INFO_KEY);`), immediately after reading it (line 129) and before it is used for verification (line 147). This removal is exactly the one-line change the vendor patch introduced, and git history confirms upstream commit f5468087c2 (Luke Taylor, 2010) is the commit that added this line and is present in the target tree. Because the cached authentication artifact is deleted after a single use, a later replayed/forged callback finds no cached discovery info: the null-check at lines 130-133 then throws \"DiscoveryInformation is not available. Possible causes are lost session or replay attack\", so a logged-out user's session cannot be restored via a cached token. The pre-fix vulnerable pattern (read cached discovery info WITHOUT removing it) is not present in HEAD. The fix is upstream-authored (springsource.com domain), not a TuxCare backport, so the verdict is not_affected with justification code_not_present. The TuxCare work at HEAD (merge of JAVAELSCVE-1165) only updates oauth2/saml2 .gradle build files and is unrelated to OpenID. [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2007-1651"
      },
      "impact_statement": "not_affected \u2014 Target = Spring Security 5.8.15.tuxcare.1. The OpenID module and OpenID4JavaConsumer.java exist, so the vulnerable component is present in this project. However, the upstream fix for the CVE-2007-1651 / commit f5468087 issue is already applied: OpenID4JavaConsumer.endConsumption() clears the cached DiscoveryInformation from the HTTP session at line 136 (`request.getSession().removeAttribute(DISCOVERY_INFO_KEY);`), immediately after reading it (line 129) and before it is used for verification (line 147). This removal is exactly the one-line change the vendor patch introduced, and git history confirms upstream commit f5468087c2 (Luke Taylor, 2010) is the commit that added this line and is present in the target tree. Because the cached authentication artifact is deleted after a single use, a later replayed/forged callback finds no cached discovery info: the null-check at lines 130-133 then throws \"DiscoveryInformation is not available. Possible causes are lost session or replay attack\", so a logged-out user's session cannot be restored via a cached token. The pre-fix vulnerable pattern (read cached discovery info WITHOUT removing it) is not present in HEAD. The fix is upstream-authored (springsource.com domain), not a TuxCare backport, so the verdict is not_affected with justification code_not_present. The TuxCare work at HEAD (merge of JAVAELSCVE-1165) only updates oauth2/saml2 .gradle build files and is unrelated to OpenID. [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2007-1652 is a false positive for org.springframework.security:spring-security-ldap 5.8.15.tuxcare. CVE-2007-1652 is a vulnerability in JanRain's myOpenID hosted service, on the OpenID\nProvider side. It does not apply to Spring Security in any version.\n\nNo affected software product is on record. The CVE record carries vendor \"n/a\", product\n\"n/a\" and version \"n/a\"; NVD lists a single unversioned CPE, cpe:2.3:a:openid:openid:*,\nwith no version bounds; the GitHub advisory GHSA-3x88-xvgr-m6fg is unreviewed and lists\nno affected package in any ecosystem; OSV has no entry for any spring-security artifact\n(control: the same query returns 5 entries for spring-security-config and 31 for\nspring-security-core); and spring.io publishes no advisory for this CVE. Every one of the\neight references points to JanRain's myOpenID security-fix announcement of March 2007 or\nto the openid.net security mailing list threads of the same month, where the reporter\nstates the problem had to be fixed on the myOpenID server.\n\nThe reported mechanism is Provider-side by construction. A crafted web page uses a cached\nauthentication token and an existing Provider session to forcibly log a user into an\nOpenID-enabled site, release the user's personal information to it, and silently add that\nsite to the user's trusted-sites list. A trusted-sites auto-approval list exists only at\nan OpenID Provider; a relying party has no such list and no auto-approval step at which\nthe flaw could occur.\n\nThe openid module of Spring Security implements only the relying-party (consumer) role.\nOpenIDAuthenticationFilter drives the two-leg consumer flow and OpenID4JavaConsumer wraps\nopenid4java's ConsumerManager. The only openid4java packages referenced in the tree are\nconsumer, discovery, message and association - there is no use of org.openid4java.server,\nno ServerManager, no OpenID Provider implementation, and no trusted-sites or auto-approval\nhandling of any kind. No openid4java sources are vendored into the tree.\n\nNor could this library have been affected when the issue was disclosed: the CVE was\npublished on 24 March 2007, while the earliest OpenID code in the project dates from\n20 April 2007 and only reached the shipped openid module in January 2008.\n\nResolved consistently with spring-security 5.6.10 (VPV 9976), 5.7.11 (43741),\n5.7.12 (12031), 5.7.14 (40534) and 5.8.16 (330), all closed as false_positive.",
      "vulnerability": {
        "name": "CVE-2007-1652"
      },
      "impact_statement": "CVE-2007-1652 is a vulnerability in JanRain's myOpenID hosted service, on the OpenID\nProvider side. It does not apply to Spring Security in any version.\n\nNo affected software product is on record. The CVE record carries vendor \"n/a\", product\n\"n/a\" and version \"n/a\"; NVD lists a single unversioned CPE, cpe:2.3:a:openid:openid:*,\nwith no version bounds; the GitHub advisory GHSA-3x88-xvgr-m6fg is unreviewed and lists\nno affected package in any ecosystem; OSV has no entry for any spring-security artifact\n(control: the same query returns 5 entries for spring-security-config and 31 for\nspring-security-core); and spring.io publishes no advisory for this CVE. Every one of the\neight references points to JanRain's myOpenID security-fix announcement of March 2007 or\nto the openid.net security mailing list threads of the same month, where the reporter\nstates the problem had to be fixed on the myOpenID server.\n\nThe reported mechanism is Provider-side by construction. A crafted web page uses a cached\nauthentication token and an existing Provider session to forcibly log a user into an\nOpenID-enabled site, release the user's personal information to it, and silently add that\nsite to the user's trusted-sites list. A trusted-sites auto-approval list exists only at\nan OpenID Provider; a relying party has no such list and no auto-approval step at which\nthe flaw could occur.\n\nThe openid module of Spring Security implements only the relying-party (consumer) role.\nOpenIDAuthenticationFilter drives the two-leg consumer flow and OpenID4JavaConsumer wraps\nopenid4java's ConsumerManager. The only openid4java packages referenced in the tree are\nconsumer, discovery, message and association - there is no use of org.openid4java.server,\nno ServerManager, no OpenID Provider implementation, and no trusted-sites or auto-approval\nhandling of any kind. No openid4java sources are vendored into the tree.\n\nNor could this library have been affected when the issue was disclosed: the CVE was\npublished on 24 March 2007, while the earliest OpenID code in the project dates from\n20 April 2007 and only reached the shipped openid module in January 2008.\n\nResolved consistently with spring-security 5.6.10 (VPV 9976), 5.7.11 (43741),\n5.7.12 (12031), 5.7.14 (40534) and 5.8.16 (330), all closed as false_positive."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-1258 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. CVE-2018-1258 affects Spring Framework 5.0.5 in combination with Spring Security method security. The target (Spring Security 5.8.15) depends on Spring Framework 5.3.39.tuxcare.2, which is far beyond the fixed version (5.0.7). The vulnerability was resolved by upstream commit dc602c0840 (authored by Rob Winch) which updated Spring Security's dependency from Spring Framework 5.0.6 to 5.0.7. The target has inherited this fix and uses an even newer version. The vulnerable pattern is not present in the target's dependency tree.",
      "vulnerability": {
        "name": "CVE-2018-1258"
      },
      "impact_statement": "CVE-2018-1258 affects Spring Framework 5.0.5 in combination with Spring Security method security. The target (Spring Security 5.8.15) depends on Spring Framework 5.3.39.tuxcare.2, which is far beyond the fixed version (5.0.7). The vulnerability was resolved by upstream commit dc602c0840 (authored by Rob Winch) which updated Spring Security's dependency from Spring Framework 5.0.6 to 5.0.7. The target has inherited this fix and uses an even newer version. The vulnerable pattern is not present in the target's dependency tree."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-5408 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. not_affected \u2014 The target Spring Security 5.8.15 is NOT affected by CVE-2020-5408. The vulnerable queryableText() encryptor method has been deprecated with an explicit security warning by upstream Spring Security (commit db155b3094, April 2020). The deprecation, which is the vendor's chosen fix strategy, is present in the target at crypto/src/main/java/org/springframework/security/crypto/encrypt/Encryptors.ja...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-5408"
      },
      "impact_statement": "not_affected \u2014 The target Spring Security 5.8.15 is NOT affected by CVE-2020-5408. The vulnerable queryableText() encryptor method has been deprecated with an explicit security warning by upstream Spring Security (commit db155b3094, April 2020). The deprecation, which is the vendor's chosen fix strategy, is present in the target at crypto/src/main/java/org/springframework/security/crypto/encrypt/Encryptors.ja..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-34042 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. not_affected \u2014 CVE-2023-34042 affects Spring Security versions 5.8.4-5.8.6 due to a world-writable symlink at config/src/main/resources/org/springframework/security/config/spring-security.xsd. The target version 5.8.15.tuxcare.1 is not affected because the upstream vendor fix (commit 5b293d21161e946bf241d9e974b9af93cfafaaac by Rob Winch) was included in upstream version 5.8.7 and inherited by this version. Th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-34042"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-34042 affects Spring Security versions 5.8.4-5.8.6 due to a world-writable symlink at config/src/main/resources/org/springframework/security/config/spring-security.xsd. The target version 5.8.15.tuxcare.1 is not affected because the upstream vendor fix (commit 5b293d21161e946bf241d9e974b9af93cfafaaac by Rob Winch) was included in upstream version 5.8.7 and inherited by this version. Th..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38827 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2024-38827"
      },
      "action_statement": "Vulnerability CVE-2024-38827 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22228 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2025-22228"
      },
      "action_statement": "Vulnerability CVE-2025-22228 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22234 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. not_affected \u2014 The target version (5.8.15, SHA 7ee34e1f12) does not have the timing attack vulnerability described in CVE-2025-22234. This vulnerability was introduced by CVE-2025-22228, which added an unconditional password length check to BCrypt.hashpw() that broke timing attack mitigation in DaoAuthenticationProvider. The target version never had CVE-2025-22228 applied - it retains the original safe implem...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-22234"
      },
      "impact_statement": "not_affected \u2014 The target version (5.8.15, SHA 7ee34e1f12) does not have the timing attack vulnerability described in CVE-2025-22234. This vulnerability was introduced by CVE-2025-22228, which added an unconditional password length check to BCrypt.hashpw() that broke timing attack mitigation in DaoAuthenticationProvider. The target version never had CVE-2025-22228 applied - it retains the original safe implem..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41248 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. Spring Security 5.8.15 is NOT AFFECTED by CVE-2025-41248. The vulnerability exists only in the UniqueSecurityAnnotationScanner class, which was introduced in version 6.4.0-M4 (August 2024), after the 5.8.15 release. The target version uses a different annotation detection mechanism (AuthorizationAnnotationUtils + Spring Framework's AnnotationUtils.findAnnotation()) that does not contain the vulnerable code pattern (.resolve() returning null for unbounded generics in method parameter type matching). No backport was provided for 5.8.x versions by either Spring Security upstream or TuxCare, confirming this version is not affected.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-41248"
      },
      "impact_statement": "Spring Security 5.8.15 is NOT AFFECTED by CVE-2025-41248. The vulnerability exists only in the UniqueSecurityAnnotationScanner class, which was introduced in version 6.4.0-M4 (August 2024), after the 5.8.15 release. The target version uses a different annotation detection mechanism (AuthorizationAnnotationUtils + Spring Framework's AnnotationUtils.findAnnotation()) that does not contain the vulnerable code pattern (.resolve() returning null for unbounded generics in method parameter type matching). No backport was provided for 5.8.x versions by either Spring Security upstream or TuxCare, confirming this version is not affected."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22732 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-22732"
      },
      "action_statement": "Vulnerability CVE-2026-22732 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22746 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-22746"
      },
      "action_statement": "Vulnerability CVE-2026-22746 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22747 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-22747"
      },
      "action_statement": "Vulnerability CVE-2026-22747 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22748 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. not_affected \u2014 Spring Security 5.8.15 does not contain the vulnerable `withIssuerLocation()` builder method described in CVE-2026-22748. This method was introduced in version 6.1.0 (commit 76eba9bd0c, April 2023), after the 5.8.x release line. The CVE describes a vulnerability where `NimbusJwtDecoder.withIssuerLocation()` and `NimbusReactiveJwtDecoder.withIssuerLocation()` fail to automatically add JWT issuer...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22748"
      },
      "impact_statement": "not_affected \u2014 Spring Security 5.8.15 does not contain the vulnerable `withIssuerLocation()` builder method described in CVE-2026-22748. This method was introduced in version 6.1.0 (commit 76eba9bd0c, April 2023), after the 5.8.x release line. The CVE describes a vulnerability where `NimbusJwtDecoder.withIssuerLocation()` and `NimbusReactiveJwtDecoder.withIssuerLocation()` fail to automatically add JWT issuer..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22753 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. Spring Security 5.8.15 is not affected by CVE-2026-22753. The vulnerability exists in versions 7.0.0-7.0.4 which use the PathPatternRequestMatcher architecture introduced in Spring Security 7.0. Version 5.8.15 uses a completely different request matching architecture (MvcRequestMatcher/AntPathRequestMatcher) that predates PathPatternRequestMatcher. The vulnerable code pattern\u2014specifically the PathPatternRequestMatcher.Builder bean mechanism and the builder pattern bug in PathPatternRequestMatcherFactoryBean\u2014does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22753"
      },
      "impact_statement": "Spring Security 5.8.15 is not affected by CVE-2026-22753. The vulnerability exists in versions 7.0.0-7.0.4 which use the PathPatternRequestMatcher architecture introduced in Spring Security 7.0. Version 5.8.15 uses a completely different request matching architecture (MvcRequestMatcher/AntPathRequestMatcher) that predates PathPatternRequestMatcher. The vulnerable code pattern\u2014specifically the PathPatternRequestMatcher.Builder bean mechanism and the builder pattern bug in PathPatternRequestMatcherFactoryBean\u2014does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22754 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. Spring Security 5.8.15 is not affected by CVE-2026-22754. The vulnerable code class PathPatternRequestMatcherFactoryBean introduced in version 7.0.x does not exist in 5.8.15. This version uses MvcRequestMatcher with correctly implemented servlet path handling through bean properties and a properly functioning builder pattern. The specific bug (failing to capture builder.basePath() return value) is not present in any code path.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22754"
      },
      "impact_statement": "Spring Security 5.8.15 is not affected by CVE-2026-22754. The vulnerable code class PathPatternRequestMatcherFactoryBean introduced in version 7.0.x does not exist in 5.8.15. This version uses MvcRequestMatcher with correctly implemented servlet path handling through bean properties and a properly functioning builder pattern. The specific bug (failing to capture builder.basePath() return value) is not present in any code path."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40988 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-40988"
      },
      "action_statement": "Vulnerability CVE-2026-40988 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40993 does not affect version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap. Spring Security 5.8.15 is NOT AFFECTED by CVE-2026-40993. The vulnerable component JdbcAssertingPartyMetadataRepository does not exist in this version. This JDBC-based asserting party metadata repository with unsafe Java object deserialization was introduced in Spring Security 7.0.x. Version 5.8.15 uses only InMemoryRelyingPartyRegistrationRepository with embedded AssertingPartyDetails - no JDBC persistence or credential deserialization from database exists. Rule 5 Type A1 applies: the INPUT type (serialized Java objects from database credential columns) is not received anywhere in the target codebase.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-40993"
      },
      "impact_statement": "Spring Security 5.8.15 is NOT AFFECTED by CVE-2026-40993. The vulnerable component JdbcAssertingPartyMetadataRepository does not exist in this version. This JDBC-based asserting party metadata repository with unsafe Java object deserialization was introduced in Spring Security 7.0.x. Version 5.8.15 uses only InMemoryRelyingPartyRegistrationRepository with embedded AssertingPartyDetails - no JDBC persistence or credential deserialization from database exists. Rule 5 Type A1 applies: the INPUT type (serialized Java objects from database credential columns) is not received anywhere in the target codebase."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41003 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-41003"
      },
      "action_statement": "Vulnerability CVE-2026-41003 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41694 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-41694"
      },
      "action_statement": "Vulnerability CVE-2026-41694 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41706 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-41706"
      },
      "action_statement": "Vulnerability CVE-2026-41706 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47838 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-47838"
      },
      "action_statement": "Vulnerability CVE-2026-47838 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47842 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-47842"
      },
      "action_statement": "Vulnerability CVE-2026-47842 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59270 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-59270"
      },
      "action_statement": "Vulnerability CVE-2026-59270 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.security/spring-security-ldap@5.8.15.tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59276 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap.",
      "vulnerability": {
        "name": "CVE-2026-59276"
      },
      "action_statement": "Vulnerability CVE-2026-59276 affects version 5.8.15.tuxcare of org.springframework.security:spring-security-ldap."
    }
  ]
}
