{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d09b70f3-b8bc-5792-9c10-0b4daef0f6b2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jcl",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1",
      "version": "5.1.6.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd895a90-d2a0-55df-ac24-814c9fbfbb76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e31e1c8b-b762-5115-be2b-3b6fb7a4c6ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c2c79d3-e5c9-5613-9943-37fb6b1a786e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3791782b-158f-54cb-a8bb-bf59ed4a38d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c280387-23f7-5e38-aee2-14b10c03469c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70663a79-42f6-50ab-9075-292aa95d2e3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20503bfe-d02c-5cc7-bc3b-123794c8937b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b1e620d9-132a-5036-b82c-4baeb03b6c9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50c4476c-3e87-56f5-86c2-bff155141f94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:208b34cb-6fe1-5bc9-b4ed-673e2e630f4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2dc98b3-ec6d-5901-a353-2bb38a73558f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6481a517-73d6-5d26-99ed-b5cfcfdbf2e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1fa6292-20c4-595c-95f4-ebf484876c55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab044611-4657-51d1-91ad-fab02688946f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f4d0691-a548-5e8d-aebc-55dd7a7e8d4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b2ca91cc-8f83-5c56-b5c3-640a04f7cff9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:184364b5-a054-571b-b3d4-c6d37825ada7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f39139c4-8173-5e8d-aa8f-3447ec02f711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:881b31a8-e454-5e01-9fcf-c8fc4882ed32",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6c9f552-9d20-54e9-8d2e-b09bf20e1259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.3."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:734785ae-55a7-5d2b-b134-0d4172deb6a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:565cb7ff-22ea-57d3-bb94-6f6123cd3235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c6a8d4ef-5c9f-5c23-ae8d-e7b1da561539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e13710c0-5214-59da-b922-3f57c0b07331",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ff93f95-bec1-5631-8ebb-1d774de40dca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b3bd53e-dba7-5cd0-b393-260384b12cd3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:58c5d4c7-39b6-5b8b-9a8d-57aadfe4d6fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c52a1df-027b-5432-9d33-4bd80dceaec8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44818ab8-7110-5a49-a2ce-49f647c12e04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd39b024-87d2-54fe-9e87-2c07bde083d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ce49df45-3775-5994-b642-8efc1d9d91a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b76e2c8b-5313-5e0d-81fc-19413067240f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl. not_affected \u2014 Spring Framework 5.1.6.RELEASE uses the Synchronoss-based multipart processing architecture, which does not contain the vulnerable components (MultipartParser, PartGenerator) targeted by CVE-2026-41840. The vulnerability pattern\u2014unreleased BodyTokens containing DataBuffers queued in FluxSink\u2014is architecturally impossible in this version because DataBuffers are consumed and released immediately ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:769ebe7a-ee7e-57bf-abac-e110cb6c3aec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:68aab4d9-2411-59d9-aafa-3ad30d027437",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62aaa25a-daf3-505a-b320-8c20efb7dc13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4445d43-1ce3-529c-b1dc-370206069844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15a92971-e28d-5bd6-bbcd-920e59693ce3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e70614a3-1899-5ec6-8095-ad9e9ae6c2ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e7380b5a-d80d-550a-9b09-0954b834f0a9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl. not_affected \u2014 Spring Framework 5.1.6.RELEASE is not affected by CVE-2026-41847. The vulnerability exists in the filter() function of the Kotlin Router DSL, which was introduced in version 5.2.0.RELEASE. Since the target version (5.1.6) predates this feature, the vulnerable code pattern does not exist in the codebase.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8e2950b-ead1-53ee-a6a6-77cada9d0d85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2a823b3-3252-581f-bb49-08bc79c47ca8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d0a5256-db75-58ea-9ffd-e63fc4064b5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fb5303c-dcb7-5fee-a629-23a677b1aecd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9009d680-5b37-5b24-affb-c098bda6d271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:877c21ac-81d8-5bd2-a48a-2c1b72f405e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8161d970-29f0-5890-94dd-716358a8f4a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:29951082-ed02-5c72-9aa4-56613a777130",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57b8adba-0a89-5cd6-9f23-71778c7e4688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c796f94-abd8-5fb1-9ed6-8524cc1d600f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b47b2cab-a5b4-569c-b82a-d092623aee62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ea6d829-f783-5595-989c-42223f5bb5cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8cfbf52-ece2-5aa0-8ba4-115819beba0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl, and is fixed in 5.1.6.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:330f209e-3c7d-56b0-a179-3e77c58b08c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f35a8f5-9cae-55a1-877b-022af0121230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4ae1448-1f1f-5cd2-9d16-fcec6d7d400a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8bb6d6e1-8f42-547a-8cc9-15540665870a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e8c9dfc-194e-5317-8972-53fbda1f6cf4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.6.RELEASE-tuxcare.1 of org.springframework:spring-jcl."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.1.6.RELEASE-tuxcare.1"
    }
  ]
}