{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c893df96-176e-568c-b540-a0ec68cb74bc",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-context-support",
      "purl": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12",
      "version": "5.3.37-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8f2dae15-0ef0-5a00-94b9-9f8f51ea6560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.12 of org.springframework:spring-context-support and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7ebd1540-30be-5b16-aa00-8cfd4fe7c699",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f4a888aa-199a-5e56-aed1-a1b843dc13fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b7da062c-14a1-5a4e-a7b0-8466e362d788",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1f920e90-cb69-51e2-8853-276268efca22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dd2f60f3-557a-55f4-9838-1a8fde445d2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b0a5a9d7-aecd-56f6-8aee-71f0b8085618",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e30f26ee-04c0-5bb9-a986-303f863b0a6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:41edda1d-15ca-5321-953c-e42b66033e95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:02215abb-6418-5805-858e-9dcd232a7f84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:937f7097-1f5f-5269-a776-4dab9aed60f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:db15436b-3e58-50e8-9fc7-e17fdcdfd52a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e383c438-08c0-58e7-96a5-0f4a8e26e19a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6a38fdd4-3b2a-54ee-a226-8c2481b1d651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c937fc39-2f3d-5e73-88db-87521a3f1a2b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d9d1ede0-8183-5223-b0e6-80341b34f5e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:043850d0-cf50-54ad-89a1-5bba45af7929",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e6fb4a4e-e33b-5bef-8bdb-de0e188878d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0362d9d1-11a3-5ed8-994e-52e33f94f3c6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-context-support. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a239bf84-ac48-5006-b4be-9a0f3b4456a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e273dbad-bbbc-58cf-9e36-73354a6ad74c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bf4e1b37-7f31-5f52-a85d-812e5f7f1a4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2cd2b35d-b527-58bd-85d4-b965a6e7da28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fe470b87-2616-566c-834d-59993595363c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ff3202c2-6867-533e-b6a8-b86fedcddab3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d6d0f08e-b49e-57ed-81f4-d6d6eaae8799",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:24606c68-e63a-51c2-9265-d43af5c5efcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e797378e-edb6-5735-b0d6-b3203f11d2f6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-context-support. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2a12f9c7-920b-5156-b839-bf77de2d6ba9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:77d37653-44fc-58a7-821a-03cc65c5af16",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b9355f06-e3aa-5b0e-9d33-61e94b03127d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:122540fe-cb9d-5404-89ae-9e38149d5d82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8fd093c2-abde-53b4-b6a8-35215c41775e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-context-support. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b583ebb8-1e91-553f-a4cd-2f81b1ee92ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:635dc499-1909-5c74-86fc-046c5aa372f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f93b542d-2bf3-5713-b833-a14c8650bb73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:41b9c808-7b65-5778-a77c-7d73d9271748",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e8e318b2-5787-567c-b316-0f949759ceaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7a6b92f7-4b9f-5e34-98e8-37f7a7b12f6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d610c153-939c-5fec-bd46-266a4169f227",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f68d58ef-7410-56fd-a142-08349718a1b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c97b5a6f-95dd-57c9-9e32-1ef3dfdee7db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6f6a37d0-db9a-5372-a301-8cac00e03480",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d3f984c5-58e4-5a2f-b4c1-1a11ac044037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:732e6dab-2144-5fe0-9658-f11946ff154e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2fe6b1f9-2686-5b75-95a4-f209d6518f47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ee057938-88f9-523e-a0cc-712957251fd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-context-support."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context-support@5.3.37-tuxcare.12"
    }
  ]
}