{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f2400acb-2d02-5318-ae0e-6516ac453f7e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.31-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f8f9c3d1-11de-5f3f-be29-44b313b25251",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ee6eeef-083b-5ef4-8966-514a7a52b15e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4445d09-7ca4-5e52-8ff4-5e13420dcab1",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7083e697-aaeb-544c-9373-501d16cd7c99",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c353078e-6920-5d5b-be4b-8ef8811d9f96",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d1733c-073a-5293-b775-4df616a39c81",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:298d8c9b-7edb-55b0-9a90-4e058de3046d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5a82669-70e8-58d4-b8b0-77af7246b19f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e19c73b-be34-5939-b51e-e041b1f26be5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21bcf2a6-9439-5564-9703-02242afdfc77",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2815ec5-9357-5ddd-ae09-67ee6943dec2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18eeac8a-594b-5987-974d-31903e8919db",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-expression 5.3.31-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63a9e820-465f-5dea-99a0-d92c59fcdf2d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a5f7b67-c2fd-5cb2-ae03-b15b9a691606",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ec0b057-74c5-5777-af59-1e105a2dd2dd",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5da03b6-36d8-5d14-92f5-c7985b5c2e4c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1305ea15-d02c-5f27-8ed3-82ef49ff5dba",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b74f399-60ed-5cf4-9c19-671073a0417b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a7ed48-04a6-5a70-974c-b2648b97cb4f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2e19c2c-b5a4-5dfa-8801-dc12e32e719a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f2a34f8-cd6c-5a62-b910-6bfd8530366e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82cc41f0-bdab-5f7d-9df0-a3788918ba2b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59fdfff0-6deb-53a6-8b2c-b9dd4ebf9398",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.2 of org.springframework:spring-expression. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93ce170d-d000-53a6-a106-75bb6a91a19b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caa7aab6-efa1-545e-a8b8-3032000320c3",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b682eeb-e018-568f-9025-f3333b9cf45e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ca1a12f-93f6-53b7-b574-b61e70ab2c1e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ad4a8df-0b52-5d42-a321-23fe1c7aa927",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c39c755-b944-5239-860e-84c11df0fdea",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6d14e6-5ffb-5329-b873-21ba173a3195",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:894cf010-f4bf-510a-826c-dd9979def012",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44c829b2-92e5-5281-9310-3613a1dadc45",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f8a9fe6-7c8b-5f39-8d32-027eb87f8108",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2e4bde0-8af4-5123-a7bc-590e9d620b94",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a5a47c-3b41-56f5-9cee-670a72334c38",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cdab96d-a9de-554d-95e0-8f16a542f008",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0288c446-f719-5cdb-a60f-01f917007370",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.31-tuxcare.2"
    }
  ]
}