{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9ff830a0-4243-5084-be4e-105e70bca31c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9",
      "version": "6.0.16-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:491e11f8-1dfc-5a3c-be97-adcb63a6795b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7de545df-59a4-5297-9f34-6f54d673377a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5c95b3c0-9e97-5203-9704-69977327fdee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fcf8ac39-70ee-58ed-96e6-b37268208060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cb252352-be8c-5384-a031-8468de575f3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e3894161-d828-58e2-8c9d-1e4b49e20981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1a92f99b-8a0f-5770-8e10-9ee026c2388a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b68b12c9-2596-5e63-9e94-26f8904b015b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:56a7c111-a0ea-5752-b381-f3018ec62e23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3e952a0d-84f1-5162-8004-58f8e097b231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7cfe94ec-2062-5059-97b2-42b08970c526",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a1160f6d-6286-5d21-8132-69355365de99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e1cfce59-ed9f-5c9c-826c-b871d86cd76b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:191b3db9-aa03-5c5c-bdc6-9ed0e4159539",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0ccd9f6f-2831-5195-a8c0-783da499b28f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5cfde457-611f-55d1-83b8-8bcbcebf779f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d2606e36-753e-5172-a9f7-0bdfa7ae523d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7a24302d-024f-5ff6-88e9-dcc674731579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ce3d0f53-1e45-505c-927b-388aca9ae5f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:45c2b10c-7481-5721-9211-768acdf6af10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1abca157-ec81-5db0-9b59-1e64a8aab515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bdcdbf5c-b516-5275-8fee-7cc6bc4b5b93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:481146a0-78ab-55ef-92a8-3edc3e819c6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a3c157dc-e4e9-5ef6-9a48-f6514a348e8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:359b4ffc-2890-5218-9938-ca5ed648d004",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ab316196-29e5-5d86-832a-9e3d9cf21685",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:eb8c0416-275b-53c7-8086-60e587e8e32e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:87e457e3-8546-5155-a486-87527d8a79a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:077d7ecf-fae6-5e26-8e54-c1ddd2519426",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:170e1a99-d13a-535b-a9c5-d2d628eb977c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fab8ba2c-2be5-5e64-a0b8-7c277bec0e48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:daf0f78e-8400-5131-b6dd-609c5c368245",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5ebc26ec-4fe2-55ec-8f8f-2757c1f2f644",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:11a7cdc0-debc-5a1e-9a97-421e64be4f67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:81f41720-74f1-5ae6-9940-70d323635a1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7cf48f1f-c4cd-5a86-af03-c33be535f658",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fdf05695-a101-59da-870a-da14d1014635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f8bee0d9-b097-5b5e-b800-2f9811fa8503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dfe7eae0-5d6d-5acc-bad3-d3a7320266c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:387bedc2-bb97-5fe1-b1cc-193894c12874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:782706b2-7433-53d5-9bd1-587744c6a22d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a593fc9a-4db1-5ce9-94e2-f4adc628baf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3e1884ac-ffd4-5434-b475-b4b8700a804c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f021e542-d8ca-5b0d-bb7a-ac4a4e926cb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b76e2e13-710a-524c-bcf5-05fb4406f97e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:05a75e63-7783-5f63-aaf4-190965c3ad5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.16-tuxcare.9 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@6.0.16-tuxcare.9"
    }
  ]
}