{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:90aad6aa-051a-564b-8a00-cc473807c598",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-expression",
      "purl": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1",
      "version": "5.3.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0624dd44-a896-5b1d-ac80-b8f34ecef49d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e20a754-f4f7-5b33-a5f5-1dbc8f869bce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d8f9c16-4515-57c9-9f32-cce23386d149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e53e6301-a3d9-58ca-ad14-f057b4647fae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4196c173-c981-5b37-9326-8cb0403f5308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2bdf43b-6268-576b-9ca0-11d514ccf446",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74474976-e67a-510e-ac99-7eff86948a79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9b6dd15-370e-529a-b51a-e9f40a6c86fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d92f37df-697d-553e-b4fd-f3795dcc44db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44fa249d-623f-5b2a-98f2-8782462ff13e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3841f29a-f0f1-5a1e-8b03-52c875d26bb9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed7ea161-2898-548d-ab0e-86dd0ac64544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b2d2faa5-08af-516c-9bfe-b9b42688a734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4777157e-39fb-56a6-b65e-142d125fc2bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5c3670f9-775a-5c0e-9e09-5fa7d4f3d32f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9d89df95-8e7f-5c76-af17-18f4326765b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fb75ef6-0b18-5913-902f-61a535feedd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:752fe16a-88ff-5a84-b78b-16a67c3b1334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:753d2f6b-50e4-5b2e-a590-943d5a6e3789",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e7bd2211-0330-512f-b769-a5336915bfb2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.3-tuxcare.1 of org.springframework:spring-expression. not_affected \u2014 Version 5.3.3 is not affected by CVE-2024-38820. The vulnerability addresses locale-dependent toLowerCase() in DataBinder's disallowedFields validation (introduced by CVE-2022-22968 fix). Version 5.3.3 predates CVE-2022-22968 and uses case-sensitive field matching without any toLowerCase() operations in DataBinder. The vulnerable code pattern (locale-dependent case conversion in security-critic...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:611f809c-d166-587c-9643-8eac80c5a058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52b14d56-1e98-5d8b-b857-0716b7e3ff60",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9087ae4f-60fc-57cb-9e65-b4c2fdebda1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c5be169-a1da-5f0e-a010-e8b0a6913737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab087492-59d5-5f7a-9253-dc5b8d271186",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01feeccb-5c5b-53c4-bb8d-c6e4a8c3fb5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a49fef80-fe6c-5602-baeb-1d7b0fdb5fa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f234b57a-efc9-54dd-b9b4-2e05242204b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dcb690dc-32b6-5eee-b97f-ea73587a0298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2129cd6-32c8-5895-b60b-74687d7e5cb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5fc43109-ddea-569a-bf4d-c2067368da72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2185a07-9d07-5423-8804-6e1e0bd64b34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d8913f5f-5bff-5556-8bb3-418db30e7da2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:868ac578-5f29-5a0c-b45a-9a7b83af9c9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f2f2318-e5be-50b1-811d-d25e1d4642a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ce818cd-dc5e-5243-87d4-62a103427852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7969fedc-ab25-5b60-a904-67c4bc2ea001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8e177f8-3170-5684-8818-ea8dfd4fe7b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9c57b58c-9fef-507e-9d53-eff2bad7c834",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba299bef-d77b-565f-9247-16822accf2ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea79c432-3c0b-5349-b6ad-e8000b471262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b6c464ae-4534-5827-acd8-bfcedc6d3b35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57eaaa3d-ba2d-5d5a-8c9d-9f4adf874981",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b2482a09-2bdb-5306-9405-54548335cfe1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f961ffc0-4de2-5a51-97ce-bb5b21500ace",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b20c9918-14dd-5c51-a8a9-b92ab05752b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa41f9d7-8ae4-5b7f-9440-e103c232829d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7ab6d3e-a58b-5b8b-aa62-f432a07d4071",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a847f2cb-4ac0-5ac9-ad68-3bf4e03a7257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4414fbe1-c3fb-5435-90d2-122ce53388c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:96c10f74-805c-5dd1-8151-cc9067ff16d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57b6a28d-a231-5020-8aa8-55aabc4facf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c479b9a-a6a6-5277-b522-716083353fe7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6dea236-6347-5953-a67c-aae03a5e41ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3bb4de91-ecd8-5e7b-a9cd-ff6cd2da40a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2fffe16-29f5-5779-b648-649a7875a19d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06015bc1-d545-5810-b04b-2048657d0305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67e6861c-a3e4-56db-9038-0c00fa4260c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73a8a674-3dec-5787-b2d4-489cd87989e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ada35cd9-69f0-589c-a1f7-5070fd31dadf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b577af4c-b532-5bc4-b5dc-0870e5cc4d22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-expression."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.3.3-tuxcare.1"
    }
  ]
}