{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fb74aa5f-55e0-58ba-bf55-c7424c39c888",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.27-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6e08b5a3-c572-52c7-b5c6-60833fccd0d1",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d432fd-fcf0-51bb-9d93-ac877ac47e2e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3fa7c74-08c0-54da-b425-66de37c26cc1",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a51408ad-7d50-5405-8d0f-5d9976c45639",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba98d4d3-5b64-5996-9922-49043d935c60",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdcd64ad-1ec2-5c26-9df4-907008e488ee",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39ef2831-888b-5f8d-a979-ace7ceb7f47b",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97ca58a-0b84-5ea3-bfa5-2ab16882a146",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee71b6a2-2d3f-5a99-bf1f-d82d0dea73fd",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87aa86a0-0b5d-5bfc-a532-33014a2c8930",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:574cb8e8-4274-5d12-9de0-7baf1a6cabf5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c64afab2-d057-5b73-b1fd-5c1ae6ca5fb1",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-expression 5.3.27-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bc3bc17-02f2-53db-b377-8a88923feb1e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9354c193-93f7-5836-b405-6339bc53ee4e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba549665-ef33-5f8d-95ce-26bb50a39bf1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b03c3dbd-907e-5c76-8067-6a17c5ba6af6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8a42e1c-448a-5529-94bc-f4b2c3511183",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fcc2747-3361-5723-875d-192f039c8a7d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f3c43a-9046-5265-8a61-eb538c8c8406",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0ab1a2-399f-5162-8ff0-c10d01647ead",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adf609f3-3c48-507b-bf9e-c30e996d32af",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935b08a7-be6f-5ea7-9abd-8471a40f233e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4807fa4e-d02a-51ec-8c8b-cb390c53fab7",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.5 of org.springframework:spring-expression. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3761f30-d620-52ae-89c2-0229e9a6ee80",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b487c41-9882-5a4e-91b1-0f76bad8dc63",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad6669bc-3f3a-5054-aaad-182ff487b4ca",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9717e229-31f4-5784-badb-cd68f1ff89ef",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d02ad55e-cdc9-59ae-871a-57d936454ea1",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4239e44-5049-509d-b83b-e0f0776e68dc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c923c34c-2273-5d7a-8034-e69c14a79b85",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.5 of org.springframework:spring-expression. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3413dcd-7974-5948-bd3f-c92f43c33b4f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f5e5ecd-baf4-5be0-b558-fb9ea17ffd00",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8d82c7-09dc-5763-adaa-7130f2c71e54",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96bccc3e-8227-5cfe-a8a5-0d89230004e5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5141deb-f4af-554b-bd5b-96327777604d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a00aa768-f0b0-535c-9bee-a51a4645579c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cff1cf8e-04bd-50ae-b315-1980bd251242",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.5 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.27-tuxcare.5"
    }
  ]
}