{
  "@id": "urn:uuid:aac778b2-675a-4b3c-aa63-0ed4ca1b7c32",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
      "vulnerability": {
        "name": "CVE-2016-1000027"
      },
      "action_statement": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2020-5421"
      },
      "action_statement": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-22096 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2021-22096"
      },
      "action_statement": "Vulnerability CVE-2021-22096 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-22118 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2021-22118"
      },
      "action_statement": "Vulnerability CVE-2021-22118 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2022-22950"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2022-22965"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2022-22968"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2022-22970"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2022-22971"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-20861 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2023-20861"
      },
      "action_statement": "Vulnerability CVE-2023-20861 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2023-20863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2024-22243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2024-22259"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2024-22262"
      },
      "action_statement": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38808 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2024-38808"
      },
      "action_statement": "Vulnerability CVE-2024-38808 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38816 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2024-38816"
      },
      "action_statement": "Vulnerability CVE-2024-38816 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2024-38819"
      },
      "action_statement": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2024-38820"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2025-22233"
      },
      "action_statement": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41242 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2025-41242"
      },
      "action_statement": "Vulnerability CVE-2025-41242 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2025-41249"
      },
      "action_statement": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2025-41254"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22735 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-22735"
      },
      "action_statement": "Vulnerability CVE-2026-22735 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22737 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-22737"
      },
      "action_statement": "Vulnerability CVE-2026-22737 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-22740"
      },
      "action_statement": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22741 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-22741"
      },
      "action_statement": "Vulnerability CVE-2026-22741 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22745 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-22745"
      },
      "action_statement": "Vulnerability CVE-2026-22745 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41838 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-41838"
      },
      "action_statement": "Vulnerability CVE-2026-41838 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-41839"
      },
      "action_statement": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41840"
      },
      "impact_statement": "not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41841"
      },
      "action_statement": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41842"
      },
      "action_statement": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41843"
      },
      "action_statement": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-41844"
      },
      "action_statement": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41845 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-41845"
      },
      "action_statement": "Vulnerability CVE-2026-41845 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41846"
      },
      "action_statement": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API.",
      "vulnerability": {
        "name": "CVE-2026-41847"
      },
      "impact_statement": "Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-41848"
      },
      "action_statement": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-41849"
      },
      "action_statement": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41850"
      },
      "action_statement": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41851"
      },
      "action_statement": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41852"
      },
      "action_statement": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41853"
      },
      "impact_statement": "not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-41854"
      },
      "action_statement": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-41855"
      },
      "action_statement": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47884 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-47884"
      },
      "action_statement": "Vulnerability CVE-2026-47884 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47886 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-47886"
      },
      "action_statement": "Vulnerability CVE-2026-47886 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47887 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-47887"
      },
      "action_statement": "Vulnerability CVE-2026-47887 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47891 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-47891"
      },
      "action_statement": "Vulnerability CVE-2026-47891 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47893 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-47893"
      },
      "action_statement": "Vulnerability CVE-2026-47893 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59280 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-59280"
      },
      "action_statement": "Vulnerability CVE-2026-59280 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59281 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-59281"
      },
      "action_statement": "Vulnerability CVE-2026-59281 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59282 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-59282"
      },
      "action_statement": "Vulnerability CVE-2026-59282 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59283 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-59283"
      },
      "action_statement": "Vulnerability CVE-2026-59283 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom, and is fixed in 5.1.20.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-framework-bom@5.1.20.RELEASE-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59314 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom.",
      "vulnerability": {
        "name": "CVE-2026-59314"
      },
      "action_statement": "Vulnerability CVE-2026-59314 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-framework-bom."
    }
  ]
}
