{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cd94412e-275e-5b32-a674-a0f2f004c4f9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.3.39-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8318b48b-6304-5e7c-968e-818feff7cd2c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34e8e9aa-11da-537e-8bbb-641c1fe5ee8e",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-expression. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a79e495-9706-566b-b2d5-f13d15e79046",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f845dcf-0f9f-5b8f-8343-4dd1d7b4a184",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12f85439-6a11-50af-ba2e-55235e513246",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a411c4ad-3b57-5a0e-bdbb-0bea8e3a1a29",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab55c0af-548c-57ae-843f-3dd6f681ebb3",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ce20233-4648-51cc-9a29-b1ce087547a8",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-expression 5.3.39-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:082cf4cd-2996-5462-96b8-a11a665e09b2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8889a18-cfb2-59cc-b018-71fbcd8f6035",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d633bb69-9aa2-5b19-9fea-945ebe13f25c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd938f0b-4db4-5c8f-aa50-8f11f11f3f23",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c188687f-061f-5aee-8dcf-950f5ed73737",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5338d695-d597-5bf8-b11d-53e251e4f8d5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab81d212-ad4b-56d7-99a6-0f8f70972c8f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d838de9f-a875-596f-bd05-4ba32cc8b70d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ce4235-e298-5d86-a6df-d077d6ec5a53",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5e9d244-4026-55ac-9ede-91908faa94b7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c5f4626-4a20-5c26-95da-537eb5fd1382",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.12 of org.springframework:spring-expression. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e20aa147-7e0b-5492-84b8-82cbc731752e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1036a754-67e4-5bb0-816c-a3bd32de5c74",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e09240b-a462-52ee-af69-ab68fd69f614",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47a19fa0-31ab-5bf5-8d44-787a27232adc",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82d59f33-c120-59b4-9ac5-42269cb97b58",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42d0f383-924d-5fce-bbb6-5948ecfe7900",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a49bf0e7-a728-5e77-acae-742c457e7068",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebdf749e-7824-51e2-8b40-4a86de987950",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2c1b2f-ba14-5322-a265-f9a1f6d17f77",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18a43be-2522-5eac-9ac3-ac54d4210f82",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7748bbfa-ad89-58a6-ba03-d92bfb7180ac",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:118b2181-493c-56f7-98a5-2f614b4387f7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3651ca38-e10f-5c94-928c-e94d375aeca8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b007d828-7523-599e-bd5a-88d46b781bc8",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.12 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.39-tuxcare.12"
    }
  ]
}