{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:523751e4-b9a2-50d2-a560-d3610e74e0ee",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-beans",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12",
      "version": "5.3.37-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2c15f5b1-5d33-582f-b79a-ea762f5a842a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.12 of org.springframework:spring-beans and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dc77b3ad-a13a-509c-ac73-3f88fbde7849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8c25326f-ec42-529a-b8ca-78d8f0936982",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c7b191e6-4b9a-52ea-a015-546385772767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fe1da58e-16f0-5947-b1f1-605b9e3fc538",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cc8fab41-ef16-5eee-a26f-27eeb9f6cb70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:22ec3486-bb8a-5fdd-bb09-5c44bc29df0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b7ff0a48-1493-5c77-a6d3-85dc8a3ac6e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3d5ce182-2941-5f96-94ca-75600d1d30d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ed505c2e-9a8a-5358-8a93-3a626b295a09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d3831fff-d8db-5d3e-afc6-52fdcd6d0c20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:17943ddf-2e01-5aba-9ba1-75d73400eddd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6a54dc96-b8c6-5a9e-ad00-61f5a07b6777",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9298f39a-edf4-52fa-94f7-06cb9170bfb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:44fefb8a-0630-5740-8ec8-79480c2efa85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b6751d7b-7cf0-54f2-9e85-43baa4174a6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:42c8b8bb-649d-53f7-a017-e8c4648783fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:32b7d2f4-82fd-503d-81c5-ef4b8aee7596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:309f064a-b228-5e6b-81cf-f750bd883370",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ad52a96d-822f-52e5-9698-931d86484935",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7c998f78-3262-5a72-9fff-0988361d3430",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b7b5bdfe-16cc-5fc0-9344-f37d2d7552b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c3163f98-35b0-5a6e-9afa-6db17f3f78e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bd3bbb10-ccdc-5383-a63d-449093d704b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e36ba1a9-430a-519b-8208-bc582b5cc804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:82d4fbb5-161e-5552-83a0-793b7b653020",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1c206f78-7b4e-5351-b89e-5b01bb961d07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1fdb13c0-1c01-5b9a-8f27-d6b41a5bc392",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-beans. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bd2f2929-e3b5-55ab-a6de-05e3640a67b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c9ea6fb9-5d45-5a2d-b484-eb1b98b82b4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:89d3f9e9-91d9-543b-868a-d599f41f49c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9b5deffb-1da5-5ca0-899f-b3d970607e2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b1001e52-fa28-5538-970f-f2bf6fa2ded0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-beans. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9ddb3377-335d-5a47-93a3-2fa70458a660",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2b5bd388-b9e9-53c3-86c2-d029ad76982c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9a0793ac-398e-595b-9857-c29e989cefb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:868ef76b-bb4f-5fa5-8a7b-d6bacd9a1feb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1a19429c-6a55-5dfc-b997-fc5b15865a1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9236a28b-7eab-5173-9546-695dfc51c9ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:055639d7-0dd6-5dd5-b745-2b41967ccd69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:327f6121-5008-5c77-baa8-452fb6c1aabd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4a0d5513-e43e-5f8b-8e06-f1568d03e001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a6541e39-0115-57f9-8906-b4cbda5b49dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d1e0b0d3-2b0f-50a4-af47-5e556d5a289d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:41486275-816c-5584-afa3-d85db4b02b50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3f3b0258-319c-56b4-a75c-9913222cf026",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:82a64dd6-9a74-5739-90a5-703745ec45b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-beans."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.37-tuxcare.12"
    }
  ]
}