{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6b4a3e63-bea1-5363-ae9f-f3bb12ca79ab",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1",
      "version": "5.2.10.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ee75456-a0eb-5190-9b70-def9ce16ad30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78003db6-af79-5e8c-81bf-c3c55fa2ed17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5d669ff-9567-5ede-99ad-b5496d9bb385",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c2a9f42-1393-5ae3-a811-dac552b2e306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:412956ef-d6ab-56a0-b34b-8ad41d3ecbae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4424e9fa-bc01-5219-99d0-cf26751adee7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87c6c0e3-ebf3-5921-9b04-97c6265bae04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e9f2895-0675-5635-af22-e7b12e9fddfa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9429c49c-2502-53e2-8da4-99755d37ebec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9159e700-082b-59da-9b4d-ec3f3e888da3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63fc0f86-89e0-51a1-b784-3e72d3239466",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:abb5bc90-369b-53af-a533-e8ea7476f029",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:269f11aa-973d-59ac-b142-1ddf9766d184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:af8625e5-27bb-5efe-a5d7-560e03450946",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54c86274-d21d-567b-90ea-4f51ab1a50bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3109fec-19b9-5f8e-b137-b358f5f9069b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:782c4c5a-0372-5fc3-b039-763ba75cfacb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d882cf4-2583-5374-adbd-f9369dfa0142",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bb1970bf-cfa0-59c7-a097-42a389dc0b82",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression. not_affected \u2014 Version 5.2.10.RELEASE does not contain the vulnerable code pattern described in CVE-2024-38820. This CVE specifically affects the fix for CVE-2022-22968, which introduced case-insensitive field matching using String.toLowerCase() without a Locale parameter. The target version uses case-sensitive matching and does not call toLowerCase() in its DataBinder field validation logic. Therefore, the l...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:236dc404-39cd-5ecb-94ce-b55bf0970497",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50a11349-c93f-5876-9df0-74970adfd5c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a3264e26-8b0e-5aa9-9b0c-dc5b5d1afec4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e016cbbb-c656-5ad0-9de9-9acc024bb135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a76c7c2-3d98-53c9-95f4-d181bdf10d1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aec8ae88-09de-5eee-b9a8-6abc7c99c3a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b556d9f7-935c-5abf-bcda-61ea235d92ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:092f4bf3-ac3e-53b2-819d-eb43c2b0ae03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf700d77-ccbd-5f69-804f-7bed58c96eba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a7f22ef-e179-5403-babf-204be86cb2ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0bb4f46c-f5bf-5cb2-8d77-2d2b44fe70f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:47bb7af0-afdf-5dda-81fc-384f841ec672",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression. not_affected \u2014 Version 5.2.10.RELEASE is not affected by CVE-2026-41840. The vulnerability targets the PartGenerator/MultipartParser multipart parsing implementation introduced in Spring Framework 5.3.0. Version 5.2.10 (released October 2020, before 5.3.0) uses a completely different Synchronoss-based multipart parsing architecture that does not have the vulnerable BodyToken buffering mechanism. The vulnerabl...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3dd7f53e-4be8-567f-a74c-2110d27eefb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba1fb70c-ab20-5ae3-9ecc-0e89d830fd43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3253515-8115-59a6-8326-765573dc3d65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5895270a-f637-5aea-b675-602e8fbade21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:58399735-e5a6-5cac-944f-a5bf99a3a56b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30c8ea21-f0a9-5cc7-802c-f4a980c76414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a7049fc-b899-5355-9fed-ad25865ad230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6485eedd-b266-5c67-b43a-46e215c91536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:09bb856e-cece-58e4-bbaf-a2e0ac0ab0c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d8fe15af-a6b9-5317-8d6f-cd066a80dd19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4cabb5d5-691a-56f0-940f-75432db62849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8d3d5ab-bb66-51ca-a3ff-b6f68e8e2e66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:942ddda1-8b3b-50ce-98fc-e78a872c3f9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f658d835-8950-5985-b7d8-56282a87d010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe3d1bf9-b1d7-55c6-8623-aa84a090c979",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c6ecac87-2a43-5403-aea3-942d55720a20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34d8f6b2-4465-5c72-a27f-7adc3b2c9585",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:19d53dd3-6b4a-54c5-803e-fae5eb9514d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c528efd4-57e3-5646-85e1-36b1c347751a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fca76bd4-e4e8-5c81-994e-fbf79b48c258",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a401827e-96a9-5683-951d-b98936050b9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f91c78b7-ab6a-52f7-a132-f9ad11752b23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:871d7696-1220-5cac-8669-c881a9020b8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5cbdd220-1b9a-558f-ab59-764bc7bff20c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:83a34957-034f-5be1-be1c-5b81bed50620",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a9a2db3-822a-5728-a427-5938bd186f1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5cf1b2a4-acde-5cae-ad3a-f65d6705622c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.2.10.RELEASE-tuxcare.1"
    }
  ]
}