{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:61ed5de9-569d-569f-ab0a-4c4ef61aefc0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "4.2.9.RELEASE-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7741150d-0471-5d18-bae6-6e7102ad10c3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0126500a-aeed-5dba-b5e0-fe90512fba21",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e6543ff-e714-5e79-8f5a-a8ee63d149e3",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2c6718e-6e50-5534-ba02-afed734a2327",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d0be49-2838-5513-a724-50a8c73a4e24",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16f2a49e-1cf6-54ed-bcce-0ced79c8981b",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bacbd2-557d-564c-ba07-da25f83bd508",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cf1ec73-3a34-5bdc-b8c0-d0f54933773d",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0004a52-12af-59dd-a37a-35b042efa1a8",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7e9c393-127b-5a9d-b6b8-7e29b2f28bab",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5eba695-ff15-5f4f-9ac2-32d0c321225f",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f25bc037-31b3-581b-b4cd-7148a18de54e",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e1f4cb6-07ff-507c-8080-205fa42b9d49",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cfc4c17-1d26-5a7f-9c22-74fb46dbd6c5",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aebeda85-d8b0-5bd9-886e-f997b4a2671c",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49aa2008-fd8b-5980-9f53-d7e747fabe74",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e71415c-7be4-5251-8f96-7bf5f554929c",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2542d23b-bf7a-54c8-bebb-b7722efbd4e4",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e3ad87d-edd6-53d5-8763-ae9f22ee4533",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:807f1336-eaa4-50a1-9cb1-187789191e2f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74549399-4282-5e45-a4c4-f166ebbd7665",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a33014b9-16c7-59e3-af8e-083cf71dbb44",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07fd838a-1a09-560c-835d-da11f27f406b",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b975076-1212-5b37-8883-b63a53f32afb",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d9013f9-b8bf-5db8-93d7-f751f7925931",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7845e94d-dafc-5b64-8e43-054c870f8c50",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc73421-d374-5484-a739-36f19de7ce3a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7e398a8-55fb-566f-96d6-cfb35e92bf5f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f87c240d-bffc-52cf-8772-9512da0ff7b3",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0d45a6b-beec-5e23-a9b8-4b11a3974d4d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5044c0d7-6f8f-5740-bee3-43c17b448b39",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1f41a8-9bdf-5552-b0e7-6d0c2efdff0a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b6d6746-0e5f-5fe8-9a9d-950f7419dd15",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70c6d557-381a-582c-8eb6-240b9e2be44c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44344ae3-75ec-5810-8370-95b72dc3f4e3",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f8df19b-120b-507e-88b3-ef3c8cdff37f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88394851-ad72-5a98-8d41-86985b67c0d3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f448da4a-f847-5a00-a54e-57c18977a0e4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4258fd44-2595-5bb7-8dba-fb08f98026ef",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8c19c9-4ea0-50a1-8fc4-e27fe9c04dfa",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f56e4934-8aaa-5246-93a6-9faf7cc40de9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fb753f5-9970-5c86-9d8f-2484e84f9c0b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1016f5ec-2876-5536-9632-e3942ea2444d",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:590a4861-7574-5207-a7d6-704e2054ff38",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb567ec-652c-570e-9024-f3134f7fa1a0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc8ef9a9-d066-5d13-8103-dc9fa60a913c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@4.2.9.RELEASE-tuxcare.7"
    }
  ]
}