{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e3302493-8bb9-56bb-a20d-80088126395a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-aspects",
      "purl": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9",
      "version": "4.3.30.RELEASE-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fac8cf89-730a-5372-a188-75597bd2341b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:541fe4e8-fec3-55e1-acc5-04507d099a9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e25ba814-af0a-5a6c-9547-42789c868549",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:df5cf22f-1a94-548e-95ff-17761bed543f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f8fc11c8-3088-5801-a79d-5d2590e9542e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b7a0822a-d726-5b0d-8ee3-719e9ca37adb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:388881b6-cc68-5515-8170-102e74ddf4ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:aab2724c-8411-5d55-b2e5-56bf5149f5fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:30aacb40-0d72-5543-8e94-0bf527c497ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4025010a-aa17-5428-8fec-34d92000d447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b7ca4536-29f2-5359-b5ab-89492860eed3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b5c27c01-b10f-56ca-bbd2-292c5d8563e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1e18853c-c1bf-5add-9cbe-f88e7a2bbcdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bc76f12e-5710-5796-810c-0cdede0cf8ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:27a2ac8d-dea4-58ce-a5e5-541e11c078e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:91b1db2f-429f-5909-8226-f55621162fa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:31250c36-11b2-5342-8c74-621104edebbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6e0d1f0a-518b-5af1-982e-9860b68e14e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:94011b0e-52b6-5b34-b34b-6dc2c8b4e548",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cd1470c3-4828-54e5-9376-e3b000a058fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c645c019-7c9f-5832-af0f-6b176f52dcc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3dafc180-1bb0-57f2-be5d-565b71aebb5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ac56ca6f-c9d0-5975-a1d5-4c8167117e50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2f98cf26-645f-5e7c-abc2-b501120b8835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a57b4ce7-e439-5ee5-a38c-4d02d1e115aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fae24747-8d9b-5348-82b0-9d103a286386",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fbe5ce77-d24d-54a6-9ac3-426b10536ac8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:57b98746-176f-56ef-8432-a24972fd65c0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:944ace03-a6eb-5194-95d4-1efd68fc8a52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9e2bf25c-1454-5ffe-aa8a-6ba9e6756547",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:58be009b-2f3a-5913-a018-983a3f38c8d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5022f6be-ecc1-564c-bed9-d864f14b8db1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:653fcafc-186f-59e5-a278-d6b3545fc8aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:28611743-9f38-56ba-8d26-9e5197bfc5ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8abb8c31-5099-53cf-b484-f28e7a7c2929",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:367e0c42-5561-5e6b-8728-8bfbd7f8d46c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:75812a6f-a2fb-58ae-8c7e-ab3125612099",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8b41e9c1-feb5-57ec-9a9b-25dc5e907985",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d4e31850-0c20-583e-9948-f6692fd2ce63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1d77446b-d6b2-5274-a15b-24284e7a6e2b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e444713a-bbe2-528c-b571-42a18f2bb223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e0fb692b-bc41-53a8-bf42-ff80420ad3f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:eb77db60-513d-5547-87cb-0aba651336ed",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:381b9b6d-b7e1-56b5-8a3d-63dffc6bc068",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5dead512-6022-5784-8f31-d21bb88e279e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c412645d-75ac-5ad0-bf18-671cd12d637f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:21ab7888-5c33-59cf-a8ad-4a20752db584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:db22bc66-b54b-5808-b94a-08913b6615e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:35757fff-c071-5a34-a013-ecc2fb6f9bce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:801cfbc2-a968-5818-af8d-9b9f938a9a1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:eb1b39b4-2493-5894-bbe6-9c10f1ce7653",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3391623a-2861-5996-b948-555e4c0eba26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8a7ee094-ef98-566a-ad3f-60c79fa9b966",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-aspects."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aspects@4.3.30.RELEASE-tuxcare.9"
    }
  ]
}