{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1c76fe2e-b005-5b1d-b05d-6cf560c556b7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jcl",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1",
      "version": "5.2.10.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b6a0a0e-fc48-55b6-ae8e-9bcae5ba4af9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c30db0a8-4306-5e7b-9dc4-d957ff0452f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e58de8e9-19d9-5b20-b587-9823d85dcd0c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ecca7505-8bf5-564a-a9e1-8ca1d716a4c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:401b934c-f1c5-522c-b664-246157623022",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1dbab127-7eaa-5649-8372-70ad2451c111",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:877cb0ee-6c8b-5adf-9fe8-572bdcc8f008",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6044ef55-894f-5e8a-aa16-e7ed86a89b28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e362105-14f1-5257-af9f-6113d83da2cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6a829338-2f52-5c33-843b-9977d127667d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62535929-d429-50bd-9239-724004bc5bcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e580f31-6516-532a-8ca8-7bb79b621045",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51474616-f189-54ec-91ad-4976129cab19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c3735a1-1342-50b9-9175-ac0d7df2ee14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76eea081-6578-52ad-9ada-40734c65fef2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63358710-2f12-5090-b1ab-c425fbad4b56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51ad22bc-1b67-5ec4-bb8f-939b8fd2fa9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f26a55bb-feb2-5007-ac09-a663fb4b219b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72476602-21ed-5df9-842c-c336871610d7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl. not_affected \u2014 Version 5.2.10.RELEASE does not contain the vulnerable code pattern described in CVE-2024-38820. This CVE specifically affects the fix for CVE-2022-22968, which introduced case-insensitive field matching using String.toLowerCase() without a Locale parameter. The target version uses case-sensitive matching and does not call toLowerCase() in its DataBinder field validation logic. Therefore, the l...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81223b3e-2359-5ed9-9739-986452d2c56e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e912872-2825-5feb-8cf0-00213b3472d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52e12af4-a0de-5999-a0a4-36a3a3c174ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ee759efc-c7b4-529f-a322-8fd6b408a782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b1149e3-9047-5652-b58e-2fe4ccfce17c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba04b835-aa0b-5b54-a7da-1f6ebdaba368",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94088b63-51f7-5cd7-8120-0b1c2b10f91e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b03f8bfa-2979-57fa-aa19-46b396497cb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da1b1747-b8ee-5894-97a5-b7a879648023",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46d2c7e6-8b40-5692-9fa2-ce0208bc748a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c981bc6-4158-525d-afa5-c73bec9e7517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5833d7c2-ae94-572d-ae23-207666109031",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl. not_affected \u2014 Version 5.2.10.RELEASE is not affected by CVE-2026-41840. The vulnerability targets the PartGenerator/MultipartParser multipart parsing implementation introduced in Spring Framework 5.3.0. Version 5.2.10 (released October 2020, before 5.3.0) uses a completely different Synchronoss-based multipart parsing architecture that does not have the vulnerable BodyToken buffering mechanism. The vulnerabl...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2fe4bc7e-19bc-5103-9e8d-bafd5d1fceea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d7d450b9-6a21-52e7-be23-f66ec9583b36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f3f69637-7679-5435-8c8c-b9f33b3e6552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d4c4d672-7614-5301-a519-c05309e606d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab500475-dab2-507a-bc53-f3753a68a212",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5f7d55f5-17c7-549c-a9e1-41aaa04111b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4663076d-7b3c-575a-99d1-1fb78bee61fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a420c62c-4402-5b3c-929d-e5599beb9a79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:757a8397-cf48-556c-8632-7e8fa28e1a32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9155880-039e-55cc-88f7-5885b13b0ece",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d14c61ed-ed93-5565-bcbf-a0ffd49da4a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:705328ec-5810-561d-b46c-5316ef231218",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db196850-6590-5efd-af26-c5dc5643b5cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1126f40f-1c28-5321-946f-27bffa0f4a6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ca5bc595-2d39-57ab-b48e-7aee6ef991da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ccae76b-184c-55c2-8f5b-d170fa3cb056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9580fa79-5556-5788-a93c-86dc5a9f8f21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b723dd2-9a8e-5784-bf2c-eebd38988011",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf9f549d-d704-593a-a15c-ff764ef4c1b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0259815e-f0ac-5b94-ade5-d6056e78476e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc3c9270-90c1-5e51-b11b-d97f93cc4917",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99471dab-0cd1-503a-b5cc-41331410ef2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d88b17c-63b8-50eb-877b-8e9e43b7e069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8747a53-4a85-5872-b1ca-a48f6f79ade4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f00c958c-2b25-5f65-ba2e-24a3b3fbfb6c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7fee82af-afe1-5aee-9b08-3ed2f9c40c7d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5c5e3f6-efec-5898-b98e-0e3914f99d24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.2.10.RELEASE-tuxcare.1"
    }
  ]
}