{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3227a95f-4f60-5701-a787-cdf165f684ed",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5",
      "version": "6.0.12-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-34053",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a7217c84-bfd8-5cf1-95df-c66aed11d4a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4c90209d-b7a4-5fe7-bd5b-b159e2d94171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ebc5fb85-94a6-586f-ad08-a9ddc7b62093",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bdfa1c2c-28c7-5fea-85e7-442500215493",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e2f1c758-4df7-5224-b6e6-695711b67c94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c12d3a1-c615-5997-8b2b-20fb302ac202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7d3a9038-ebcc-56d3-abeb-3abad99511f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ec3ae5de-6532-5f04-8d38-1b77f17590c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ded3dd2f-691f-5d9a-a64f-1e0a224e5978",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fafba04b-d69e-56e0-82df-886eef3dfb17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:489462b3-13e8-5299-b9ed-d65fa9594082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:30fe9b47-daec-511a-9760-1b1bff2a6032",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8d3853ce-5cea-564d-844e-50d288d0bad9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3f201712-650e-56c2-8c90-4de2842f33e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:05078425-82a2-565e-8291-e1f30c0ecb99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cac0d33a-bf32-5b60-af61-fdb515e73592",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:349a2772-50c1-5822-9402-09ee134533b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dd821c2a-0c8c-58ac-b6cf-adfa270115ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c9bb258c-d392-5c51-878f-1833262a47f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5359c3dd-437c-5871-aa2b-ea71c2f39cb0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41839 does not affect version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom. Current version of spring-framework is not affected by CVE-2026-41839 according to the vendor - https://spring.io/security/cve-2026-41839",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0d587658-6caa-5e0d-b1c4-90ea90f556b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d00eac63-7787-5225-996b-96d9c13b965b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:91d9c7eb-81f5-5b59-a890-fd9a32f47b7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:344c7e99-1990-5dfd-975b-ce086296aaca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f5a970ad-7c8c-5fdb-8c4f-186f75247837",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:137feef3-69f2-5829-b0e1-30aa9151b16e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:26af1fc2-a0cc-5373-ad35-cb9a98280490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5f7c6e7a-4c2d-5478-a84d-4c6c6beabdd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:41c6e00f-3fb7-51f1-ba04-b70e55097740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:680f2bff-5c51-5cd0-b632-ee79e6f14c77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bc776b3e-ce56-57fe-b8fb-a7f71ac09e38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b4df81e6-eceb-5c84-a71b-8398f55068ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c87f788f-134b-5850-8d83-e90582857ff2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6b61f458-aba8-54e1-9689-a2e13318d5ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:05907e43-a855-56ac-92f1-d8191edd1912",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c20796c1-51d4-52f7-8d2b-05775180a923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c6e5ded3-ff62-5520-8f17-97888291050e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dbb740d4-08e2-5210-af13-c9b042f789fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3fe7cad3-c994-51e6-b0a0-78ac3df0339e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:363c37e8-8a24-510c-998a-33c98ba929f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4c57ec1e-91f6-57e2-bee9-6f76c1e1dd52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:039be340-9946-55be-9aa1-cb4122e99a12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5cb9f389-a46a-57ac-ab64-e343d38acc1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:03508886-5720-5fc7-b174-e2ffd9cfcee1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f3953292-c9ac-51f7-8154-ad27a7486bd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a7b186c9-6294-5073-a563-c35662a71da6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f53688b6-b054-50a6-85a9-ca9f3332a77b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.12-tuxcare.5"
    }
  ]
}