{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a4065e85-8ff1-5d82-a53c-5fb29a0b49c2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc-portlet",
      "version": "4.2.9.RELEASE-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d4520c26-d5f2-5c20-af3c-f409f30ed0a4",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4b57d04-c736-5fae-92cc-3066fcdadaa1",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33e6bb7c-c5f6-5330-a918-9dabaf52de67",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d93dceda-39db-5aca-825e-def050070130",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87519329-8d8d-548b-9460-acc77736ce06",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:477e5256-06c3-527a-aedc-4e2b66ba66cb",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80685dd2-a1fd-529a-9526-4ee8822551d8",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d116fe-79c9-5a06-9a5f-ac99e754cd79",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39fe6752-c9a6-5994-80f2-c6cbf571c534",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0bbf657-3a98-5983-8b9f-b3bc6b59b2c3",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749ee4fb-979e-5b52-998e-a95f890d54dd",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c93e8b1-d779-5904-9ee0-d9da509cf941",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fffe0d9-5c08-51fc-ab65-02859c44f344",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d95e89f-ce4a-5f3c-a117-3f435d87a8b8",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60b2e7be-9c87-537b-ac6b-9b9b2a1da3c7",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7d38c5a-d2ef-5790-80c4-67e26976f62e",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cc23fd9-78d3-50b2-a0a8-5fa6e81547fc",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b71c153-cadf-546f-b9f1-cf302ad599ac",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51c59f88-17ef-5a06-a5f4-f00049a3f546",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0013574-1cfe-59a4-b4ae-b7578c713ab5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08213c32-2065-5e4d-8c8d-717e69bd7807",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d1a4c7-6c1c-5eaa-874f-af51b5b43277",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47069107-d92b-5b7d-8396-47f459092008",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:415a94b5-829e-56d4-b826-17322f85e75f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79e29d7c-9a29-5297-bace-2f3cc9b06c98",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02cac76f-5915-59dc-8944-0b0daf7cbe68",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a040b2e-7046-567b-8ed2-a7726f8cf5d6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b8f2af6-0531-5a32-a7f8-95c93635100b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:691008ae-acdd-5a33-82eb-2c1d5483584e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b25c3bd-52d8-5221-8bd7-dcab20030247",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb2b0332-5673-50a2-8c25-7e10c7f53792",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c730325-448b-5d71-8d80-8d6233ae1114",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b71cca0f-21da-5efc-bedc-fafced00dae1",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dcc64e8-fc8a-5415-a3d4-05a66519be70",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1da1e135-cf9e-5dc0-88bf-164d719cbd48",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d02fae-a79c-5ce6-bcd1-fc037b4d01d2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f50a0447-d1e8-5d48-9fd4-f8af24efb643",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:434cf7dd-a0eb-556f-855d-f7add3123d36",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b1b90c2-4e9f-544c-b827-398a513443c0",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0a5b320-db68-509c-84ac-81194d184ce9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9b9a77e-c19a-5d9f-8d68-2e8e4f186c85",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:811c3cc1-78fb-572a-a3ca-5466535b0de2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c14fc5-04bd-501b-a103-169a76fab92a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a889e408-810c-529f-8210-fa532c0569a5",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:288d9117-46f6-5e47-be4d-b5bf5603a083",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5be6ee95-8372-54de-bbce-855e979f90e4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-webmvc-portlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc-portlet@4.2.9.RELEASE-tuxcare.7"
    }
  ]
}