{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13a708c6-a1db-5d5a-8f02-7da3819ed996",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-expression",
      "version": "5.1.9.RELEASE-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7e6dcd5d-194d-547c-80b5-7224d9cd67fb",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a329dda1-0c22-589d-8f10-63b0e27b4404",
      "id": "CVE-2020-5398",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a314ec56-f6e0-5fac-8394-544261a7c674",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:065fee76-be47-5061-ad98-36745f369e57",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4540c662-98ad-50a7-b565-d4ffc9d3273c",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79055f65-06bb-5ab9-b82f-1fb619c8d456",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52be756f-687a-59ca-8675-1affe720e9f8",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14ee663d-5c59-56d4-8396-117b34556edc",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afbf8a3a-12ae-56fb-bf46-feeb6b57d6d1",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74f4221b-b821-5541-9ad3-5a11d80171b9",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea71f6f-6399-57d5-972e-45241eda5738",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a172d121-11c8-5672-af20-985566107fee",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3dcf208-c533-55ce-9898-6794866fb828",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89047a89-df06-52b7-a03f-06bb2c55abff",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13ad8fab-8387-50c0-bc0a-9a3459a37609",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18f25630-a48c-50d9-bdb4-0ff0f0f1a5ed",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7167a987-5fd1-588c-96a3-649bd601a5ef",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db25fb4c-936f-5ec7-bfa7-edf80ba75a19",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5320fb70-2feb-50b1-ab2a-e6ce506df3f3",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ad681d2-88af-53ee-8207-a5b6b7b1b499",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60ea31e7-3007-581d-9dc1-96c771893169",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51901963-26df-5668-8352-52d73aa0c3f3",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d47aa1d6-7557-57bb-b35e-846b478ca9f1",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e43d120-59cf-51f3-b78a-b87f9e046ceb",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0f36720-2d91-5aa8-aeaa-489aa71cc012",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.9.RELEASE-tuxcare.2 of org.springframework:spring-expression."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-expression@5.1.9.RELEASE-tuxcare.2"
    }
  ]
}