{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:62d6d673-0c6b-5288-ab22-05142dd8c484",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.30-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f581b539-7082-5f45-aca8-c5092f685934",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253125a1-04d5-577c-bd29-8606348449ab",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82e6cb99-97b4-5512-b412-de6755559ff4",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff5b859-9365-553b-9dfc-facde96298e1",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7008e756-ad43-571a-85f8-cd7e7fb2775f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b93568a6-f5d5-573d-94f4-ac74ea0cc9eb",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae365f83-2e4b-599c-92a7-23dbb45f23b2",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:930cd74a-51ed-5ec7-8971-2a8fd0b6bacb",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a885286-8b82-5135-b7fd-3ff17c56e455",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff271db7-583b-5813-9915-fc8faa6a436b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81381510-0774-5343-9b6b-861ca21e5dfc",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e92e2ba0-0804-548b-bb13-7063422e29a7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0cf5982-df58-59af-8dde-f1819185415b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cda199a-723d-57cd-b741-14829cb01190",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9156c105-420a-5a2b-a66b-87bef1ad5442",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c968cb7-8ca9-5b71-8766-6bd91a075d8b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:284756cd-a007-52d3-94a1-2281ff1b9112",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc975f7e-bb4c-58a2-8421-8aec54be3c62",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d77a7d11-2506-5450-af6f-1c90787d165c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6561f89e-b979-5289-b289-21033a2132ca",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:055e1398-f35a-51e2-9861-4bafe7e81b95",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64073222-ce61-57a1-abb1-b8e3134167cf",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.1 of org.springframework:spring-expression. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535db134-de6b-569c-bb46-ad43363064ad",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e34256e6-e122-5fc1-b7ba-10705f1a37d1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50772fb5-d2c8-5c55-bf02-bb853dea8d6b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8019da31-6a01-57ac-8d81-8c72aa433b2f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:410b9bf1-50f8-5790-a3d0-7895b8167ca4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796942cc-8ea1-5ea3-99b8-a42356b90526",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:deb2373b-b46b-5e56-b6df-de7b0e541a4b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bebaa09-a2e4-5e87-b5e9-fd21c48b6ad3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1fd3ac-d16e-59d8-b004-301ecadcf11a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f198456-648b-53a5-bd47-a9d5e43247df",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff53074d-affe-512d-84b6-4c147ec0e1e4",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:452bc5d1-52a5-549a-b9b1-ce11900571aa",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b9634fe-3afc-5462-aba5-4d735a2c8e4e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9398178a-8d7e-5640-9c97-88dd3e75d7e6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.1 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.30-tuxcare.1"
    }
  ]
}