{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:49f5b4dd-27a7-5edb-9796-cc29e5997c06",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.1.6.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cd895a90-d2a0-55df-ac24-814c9fbfbb76",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e31e1c8b-b762-5115-be2b-3b6fb7a4c6ea",
      "id": "CVE-2020-5398",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c2c79d3-e5c9-5613-9943-37fb6b1a786e",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3791782b-158f-54cb-a8bb-bf59ed4a38d0",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c280387-23f7-5e38-aee2-14b10c03469c",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70663a79-42f6-50ab-9075-292aa95d2e3f",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20503bfe-d02c-5cc7-bc3b-123794c8937b",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e620d9-132a-5036-b82c-4baeb03b6c9c",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c4476c-3e87-56f5-86c2-bff155141f94",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:208b34cb-6fe1-5bc9-b4ed-673e2e630f4f",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2dc98b3-ec6d-5901-a353-2bb38a73558f",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6481a517-73d6-5d26-99ed-b5cfcfdbf2e3",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1fa6292-20c4-595c-95f4-ebf484876c55",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab044611-4657-51d1-91ad-fab02688946f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4d0691-a548-5e8d-aebc-55dd7a7e8d4c",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ca91cc-8f83-5c56-b5c3-640a04f7cff9",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:184364b5-a054-571b-b3d4-c6d37825ada7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881b31a8-e454-5e01-9fcf-c8fc4882ed32",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c9f552-9d20-54e9-8d2e-b09bf20e1259",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl. not_affected \u2014 CVE-2024-38820 does not affect Spring Framework 5.1.6.RELEASE. This vulnerability is specific to locale-dependent toLowerCase() calls introduced by the CVE-2022-22968 fix in 2022. Version 5.1.6.RELEASE (released March 2019) predates that fix and does not contain any toLowerCase() calls in DataBinder's disallowedFields processing. Without the vulnerable code path, the locale-based bypass describ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:734785ae-55a7-5d2b-b134-0d4172deb6a5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a8d4ef-5c9f-5c23-ae8d-e7b1da561539",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e13710c0-5214-59da-b922-3f57c0b07331",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c5d4c7-39b6-5b8b-9a8d-57aadfe4d6fe",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c52a1df-027b-5432-9d33-4bd80dceaec8",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44818ab8-7110-5a49-a2ce-49f647c12e04",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
    }
  ]
}