{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:da7efa20-e1fb-5e95-a733-e4be441ce6ad",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aspects",
      "version": "4.2.9.RELEASE-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bb8c8087-0cfd-596d-8ef0-b8f92724e5d5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:246a52a1-4ec8-5214-ac27-459dccc9a8d4",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56e38d23-a1b7-5a3b-b08b-8ba2206df1c4",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49419bd6-32e8-51e4-87e8-50c781959cf9",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f10e9469-30de-5e51-b5ef-3263c3b40258",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e511e611-a2b6-5a04-bbb1-6d105467fdf1",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:788c003d-538f-58b8-a1f9-d60368495e54",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dc372e3-ecc8-5575-baa8-a0a4ea3ff63d",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b57958a2-dc83-55c6-bcf8-e48e6be84b54",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b34c8b22-2d34-5cb3-a92c-9bfa7764a424",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0f43a91-5383-5f60-b864-016c39f222f2",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aab45db-0973-518a-af1e-5fecc340b19d",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8527fc24-f531-5706-8ca3-970bc4d3436a",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:490356f5-befd-5a12-aa30-07c666287461",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf16cef8-8ddf-57f1-bab9-5089bfc438b0",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04983d9-e55a-5448-b21b-6468af3d51b6",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03cbc36b-a03a-5f67-b1b0-5665c2fad693",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11800067-f10d-5d4e-aa4b-df6564befd22",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb40abcf-aa19-5855-85c9-bfb3989462d7",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae638364-64e8-5cb7-917c-e6cf6f71a2a9",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06b7931c-e10d-530f-84ad-1ff33ec2d8e4",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef310c39-c60f-5b55-8163-79d37063a66e",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e7de482-92cf-582f-9b1b-e1e3760f014c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f4ee83-b195-584f-8fc1-b99b8d6dceb7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c26a9274-5f37-54ee-b755-71b5301ace6d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17b17860-115e-56d2-8022-f3c4c5a3788e",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e60bbe-39fd-5cdf-82da-73deb83c4325",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75817ec1-2b0c-5e94-95ab-1f3f4866f4e4",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9b15d6-cbb0-595e-be05-f445db33a540",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6bc2885-6e79-5660-921f-6ddc79fa0044",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:927dee47-65c7-547f-8fcc-1c853c76b67a",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef81696-3b76-516e-b894-6d1e06df13c8",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb292b6-c43e-54fe-9a0d-6551d52879b6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:663f4a6e-3900-588c-9f0e-65299806865b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97157d31-c985-517f-bc96-2275913caf97",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82fe5969-3944-51de-93b0-c10ffbd2f9d9",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a132ab37-809e-593b-a079-ed5c07a46b7e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7402ac23-9dc5-55fa-a52e-2bf9bba23a7a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a22de1-fd05-5e24-8549-219372ac6569",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf560c4-fb15-5f3f-a1d3-7c9a783f8a5f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06203f53-2f24-54f2-96f4-bf5f9f4c6c37",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700e86d4-8d2c-5973-9616-140a921ff4b3",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80c48f02-b1d0-55df-86c5-e1147a3f4ecf",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fafcc1ed-3102-52bb-ac07-1414abbc85b9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d5193d-6934-5b62-8cb4-5210d0fd5ee8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7535084-1753-5004-a21e-8adbb76676d1",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-aspects."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@4.2.9.RELEASE-tuxcare.7"
    }
  ]
}