{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7c3dcd7-c32c-532f-b65f-0779fa3a89f7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b42b4ee9-06c8-542f-b8f8-a5e4be908679",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3db4188c-5f79-5306-afc2-3613832e9d6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e23b52c0-5878-5b13-a33c-06850f2f78dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:236be7d7-c23f-5b31-83cc-f0107837b592",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1293f315-5ff4-51f0-8134-1084aa1d5ce3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d5e6cb73-666e-5b3d-97b9-2804836455a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a5450a98-69ab-5fc1-9a32-96f7970a5f6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8366ce3-5723-51d4-83b4-753414210700",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e563ef54-ebd0-51e2-b9af-c9c1767a5fbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:57b80294-c2d0-5691-bc5e-487e4bf0d9e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8daf8066-3a33-5ed0-ab0a-8aee9658ec62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c642df96-6655-5f10-b5f9-bf2e69048900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:053fb570-b69b-5fa3-87a6-a7aa2b824ada",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3f725fa4-ed7a-5e35-a404-e6ea91dea582",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:926e02fb-b06a-5002-8f93-c9f146bb709f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:469a639c-6152-5ac3-a479-1632f6fa3d43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6c61eff2-fb5a-50cb-9365-151a3c0152b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:776a6f12-8b3d-519d-ac60-33b84208be87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60cc9026-2fe6-5158-be3d-fe5a63229c92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f1330378-b17a-5f0e-a4b0-96a76cb3caf5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e747c9a7-aa3f-5cc9-b081-49f5675f91ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:707a0d93-4bfe-5f4e-bf27-6f4259bec376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1a9778a7-477a-5ba8-a724-450042d287e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:386357a5-dee2-5b97-bf0c-db60252ad2a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:085ee24d-84a3-589b-8db6-4aca7cd87e7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:02e68f87-dcb2-5bbf-beb5-4fd15a55b360",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:93273850-6dc6-5d28-879e-2a88e2b3d4d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:36f270bc-d602-501b-bcb9-69f688d9a2de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:334c782f-d97d-530a-b2f3-1363a43624a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d27e0763-8c99-5e9b-af82-2f4b9b9690b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e6c0fc7-c5e9-5dc4-8f7c-65ba1c5a6e2f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da58a9ac-97b0-504d-bf36-d1affd6998be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b55d1d0-73f4-5238-bedd-12cbe0dacb08",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4154482e-773a-5563-97dd-0b4defe6c01b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca289bfd-82e8-5267-95b5-cd4ef340e4b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ec6d3aef-e576-55b9-8019-962d22a0b915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:956faf4f-e664-5ac9-b1ed-7c837260312a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de822157-8217-5f31-b3a8-ff89e8d368ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e516c9ea-fa33-5b42-ba3b-218e74acde00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b43cc28f-06cf-506f-9cbc-7de51706ed8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:22aa0656-fb21-5cff-b09e-92be1d31cb57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c99af8c5-0751-5c9d-90df-822454521a3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e022747-7098-5ff0-9725-eddbcebfdd2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:83d9f2a8-b328-5d47-b4d6-6d5241cdd6c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a1c4e600-edea-5781-ae03-1bb440a57dae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17d55f02-61d4-5582-b80f-d7d41cbf2516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7b27ee68-83b0-5f6c-9379-75e14ff4cfc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f154fc37-77af-5888-a300-1d23dab6fc5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:22b6d34b-99b4-591b-b5cb-2ed78f2ba29c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e3e21b4-34d6-5067-b472-04b7032888f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a1d77a20-f5e9-5dae-a5e4-defffa155ab7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c79224b4-3563-5594-82ae-065b9b392dc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e186ef9-39d6-50d3-b51b-8346ca835d07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8c4b51d5-3aee-5d8d-9642-d6b7e6423a1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c70303b6-ad90-5190-84fd-f7c4a3125b3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0486098e-0167-5a1f-96b0-1674103b286c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e4ef41f-769c-57fd-a84f-86e9b95ccb67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00536455-44a8-59bd-a282-08b8cfd66ba8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8787c286-487d-5280-a20e-ed7ccad44370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:969e8457-cd08-582d-ad98-0d66d3f9e3e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2579ede-2d46-5a1f-9c39-f5dfdc330759",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.6-tuxcare.2"
    }
  ]
}