{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9c5499c9-9b9b-552b-ac39-771c3f9bcab7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1",
      "version": "5.3.20-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:110c04c5-53a5-51e3-b394-b6fe0ce179cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:feb0af01-2d7d-5bc8-bfd0-b61fe76e5648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4ff3348-7508-5d17-8ad9-ec2c73c0c03e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8457a7cb-7cbf-5449-ab96-c08e16238111",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e78e3142-ea08-5a52-b665-15996cd55954",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:286bb717-2f1c-5fbc-8a98-62dc64bf3198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2cc57f5d-053f-56d8-8dea-066f9e4f049e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9164ba3-39c0-5f61-89e0-de8fa4cd3949",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7bf333ac-e363-52e0-8651-bc9644078ad4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1253abcb-bdd1-59b6-a6fe-7286bbc8aeb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:edfeaf6d-2ec8-59d6-92e0-ea20b9d70727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c21a416b-38b4-529f-b48d-24bf98184c09",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4334c0f-bce9-5fad-894c-f6f717c312a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3c5061d4-aa81-5441-9075-8dc19f8d45b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27f1953f-0b9e-514e-9c2f-c637afb0e076",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:771caa7b-24b1-5ca4-b595-23cd9612428f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b88caf7-0aa2-5155-95f0-5186a9ba4b66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16e07fce-6c14-5283-b1b6-0214c3157345",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b2d3a66-b53a-575b-8533-2625155165cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac87d745-a29f-5a7d-8858-c293d61f384f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ac8febe-6dc9-548d-a597-2c11e10062c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4724e491-5224-53fb-8bb3-9f07ef057471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dee61a86-4265-5e31-bebe-f24bfbebe8ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c682aa8b-3e10-5c58-a368-30bb58a7f7c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:22eaffde-faf5-5ea2-b14c-7b40fd858615",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9215f41-689d-53de-b5a7-c90391c25b8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ac4a5b2-5e9b-5dbb-a312-248965165b5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b1d2696-5049-56dd-9c5e-f21554907301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da072ad0-bca0-5a0b-afb9-527a3481f0e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bfbba7b4-ce56-5a6a-9526-beb49eb0176e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75222509-1f9b-52d6-9d23-ad45327bcdaf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73a2275b-30ba-586d-8aba-4765d7b6483f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:11ac7fe7-9647-51e6-a762-188790c9353c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe8e0657-d38c-59b0-964d-a9ae1906e18b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4ee8663-3494-5599-bd4a-bf41ef459868",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02be2c05-020d-5579-8aff-2c4d7f51fa82",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66d18bf5-70c6-5cef-a7e2-f37d485cbe76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:705e6c33-9bbd-53d0-9e6b-3a5a871a8f00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:006d180a-8166-5f0d-b4ac-16e6cca2ad52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c47c2676-80f7-5c3a-8ca8-40f805221878",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37ea679c-e193-5bff-8c76-29b9de2cf709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0b554be-7cb0-50df-8c0b-45695d3676bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8def2712-200c-5a2f-a027-0c266d80466f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad13a529-3049-5371-9b9a-d77b76673528",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7dde6817-7877-53f0-8e73-8879d671d0bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:599b2514-9eaf-5407-8adf-87ba141957ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa9deaf2-0236-5cf7-8e59-f13c867a27c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d054029b-1741-57ae-8956-2f86a67d36ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e60032c7-56c4-5fd7-9be5-12911c66936a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d611a574-0ff2-5989-ac80-c16d2fff4242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6232742-64e7-5faa-9021-ed44217e6914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10cecb6c-3c03-5fdf-ae7b-7d0fcf85318a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4a67da1-2138-554d-9815-d502f8553019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.20-tuxcare.1"
    }
  ]
}