{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c2196a28-c295-5684-9f4e-7f0155112603",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-beans",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0afe3f9-fcab-5801-b7a9-362e203d74df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ec16de54-47da-5204-8218-cf43f66054be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:332f492c-a79e-51c2-a8ce-9d15f9654b5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:47184d34-0c5d-5ed4-b400-e10db1ef972c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:56b1fd92-f455-5f02-9da0-974405154e0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:656fc730-4749-5717-a7ce-e2d82ab750b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:784ac5dd-d9b8-5625-a79d-06ed3627e776",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:026fbbdd-e988-5442-bcf3-e98cb82f890c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9ee8908a-9ffe-5625-8061-82b500d2610e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7539dd49-a2f1-5d90-9914-ea245447d457",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a5b2b715-29f5-5800-8604-d5f63248f819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d0d1e9b1-4e53-5add-a933-187d49d0e60d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4645906a-c64a-5688-b064-2a70329da1ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e04ce245-cae2-5aa8-ab1e-ff9ae8b49ecd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:444ebc27-dba1-5b23-a798-44aa9c048def",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ed6fcc4b-c55a-50b9-8cb5-8335daad34d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dde2a098-851b-58ed-98e5-6cd245dfebb4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8ea2c11c-a996-5699-a11a-051d3022dea2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8814a777-6c70-598a-ae08-2a5c26ef2c1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:628dae2a-8425-5f1a-a593-c0e733100b9b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-beans. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:10627ba4-de39-52d3-b285-72c44ed9f9c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:120a5b6e-328b-5d69-a59b-b2646cc4acc2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8865c98b-9fa0-5f43-b32c-e1362811ada3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:31df49e4-59e3-5c01-8d56-70fb657eeb7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2503e6a-c995-51b1-b2c9-7f475a1d82a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff7c8b96-af85-55e9-9849-a70740f2d837",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:736b4da5-d2b4-5216-969d-469f5d0e57b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0bf0ff36-a4e2-5f3f-be8b-69f47127d978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2cc15564-abe6-5708-a77b-d002d756a058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84bdf95f-01a4-5b3d-87ac-94589504335d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3855ad5-d7d2-5ef2-b767-c940273e7349",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:81097158-e044-5f28-a04c-790ebe4100bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d912df78-b73d-5403-bd22-7d222aa6dac7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af815659-b527-5936-9b04-62e748d54f92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7f365d8e-1b4c-5b7e-82c3-b14aeb59c3b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4beeeade-e31a-5042-b6d5-7a54baeba151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43fc4e77-567a-52a5-ae3e-4f010154be1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d9eac2b6-7ce0-554d-95f1-a0855848cb74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5470d89-d630-5d8b-9196-d1f88b16196d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8f81641-56f6-5684-a2b4-b808e11ce35e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:50827d5e-19dc-53c0-9da7-a2218b97a5f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5df2a3a3-5bd2-5456-8be8-e9df89c50735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:215f82eb-3c07-57a1-85d6-5d2d090f75d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8647b125-0e8b-5276-994b-e1ce594f5f99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5644c9f5-e39d-5f1a-abf8-ffa1026e169e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84308770-2b20-5902-b6be-a2510a02d012",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bbdc381-4bea-5116-a7fd-411b52f243a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:66107401-74aa-5389-9681-57ac6c9e44b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5fff0532-fa22-58fa-9144-d21919e0ca7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dd8b0c0b-4260-5446-ac86-92e3c74f69f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eb3e0a52-7ead-5566-b2b9-bb1c2396e1e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:71e40db3-cce6-5cd7-b0c4-38d2d2ba4877",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:72f34812-03e2-569a-8046-9cb183152625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6bfa4e14-ab40-5368-af71-0001b73018d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a61e8a6b-e1bb-5eca-a1ab-21b814ca96de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1468ba23-5e6f-57d5-88b3-9d21d0124ea6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0368a7e-9eaa-5500-b404-a02b5e5dae61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c8c1b4e6-1c17-52f5-ba9c-f258c01ec46b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d4e8e4b-6be8-5f2c-86b7-2fa9406dd3ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bf14763b-06c8-5ae7-8233-ad896a8832ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:edbbf5ae-45dc-5548-ae3c-f5fc44e9167d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-beans."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.6-tuxcare.2"
    }
  ]
}