{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:930d771f-3467-59be-9d79-b7da67af7ac7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1",
      "version": "5.3.13-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:888a38ed-1393-5982-9a63-7d4019deee19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a45a4900-2de8-57c4-bc42-d1a7a21306c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e6139e7-2be9-50ff-a49e-0438875f5004",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d7b5dde-71e0-5cfc-b0f2-2270a7cee370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:412f33fc-6130-57eb-852b-025b78858d48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:909a74c6-239e-540c-90d4-9b00c4936a4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e76a2c8-a762-5e48-b3cf-c9d7136ae1ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38817176-79aa-59c1-a8ed-4c98bcf5ec9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:77add727-aea1-5221-bef3-23a2ecf01a57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bffbe62b-a2f5-500f-885b-045c7a1d6fe6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ffdf105-2561-5e57-94cf-c8800050f0dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c3b2405-6663-56b0-80fe-24f6a97e5eb7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dba5fb55-b3f0-529a-a458-ad2df8a94933",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51345536-28b3-552e-bfa8-b0f78ca59129",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b3cbe05b-9d05-5f0c-bc13-e6130b4a5f24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:183eb531-fba2-5c9f-81e4-8aee21ba71e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ceabdffc-085e-5d75-94d7-230fc1b94cb8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ee224fa-a131-5dea-9a0f-019d397ab256",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.13-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Version 5.3.13 is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() bug in DataBinder's field matching, but version 5.3.13 does not contain the vulnerable code pattern. The CVE-2022-22968 fix (which introduced case-insensitive field matching using toLowerCase()) was never applied to this version, so the locale-dependency issue that CVE-2024-38820 fixes cannot e...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0bfb792-bc9e-57f9-8649-8bbf16dd9049",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38828 does not affect version 5.3.13-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 5.3.13 is NOT affected by CVE-2024-38828. The vulnerability was introduced by an optimization commit (gh-31834, 0970b1dc7a) on December 13, 2023, which post-dates version 5.3.13 (released November 11, 2021) by over 2 years. Version 5.3.13 properly allocates ContentCachingRequestWrapper's buffer using the contentCacheLimit parameter, never reading request.getContentLength() when...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69d22f1f-3702-59c3-841d-eff5ba60347e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c771e2e8-a776-595a-a814-b933bef0722d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8919cd2e-43c7-5ffa-8efd-d1bc00f78f7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:451397f9-f833-5ab2-8649-29cb77ae3a40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1216bc6a-4194-5d8a-a0bd-b2032921194a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:561c1a9d-f93c-5413-be45-755dc0e2b700",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b211489b-59b0-52be-b1e4-41582788a362",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f316016-9dd0-5a80-b2cc-d4a29dead093",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46e66a48-ed8a-541b-82bb-ad2633a9443d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1fdd1fb3-eb49-547c-b5f1-0fcd040b684b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4dd92005-0b16-59bd-a362-fc021e3ff342",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:676207f0-4911-51e5-ab9d-495a633c6d37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4241c0e-40e9-547a-888e-deafb0d3f2df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94a500cc-6fc8-50e8-898d-333fdb32e32b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cfeb0eef-eedb-5bee-9408-84b5a8845275",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a17a835-74a0-5fda-91a7-b0310b6f6ab4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5007960e-f42b-5034-b79c-5f04013627db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:29b05181-0b9f-507d-a762-a2e1318ae867",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e852ffa0-c826-589d-bbcd-1c8e99b2eae7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85169fb1-028b-5012-99c4-465679f12763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59aafaf0-63b3-580d-bf73-7c3b30f026c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:369a9304-ae80-52fd-83f2-7dd9629cb40a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20ffd6f9-a697-5b8c-ba5a-bed5222ed9f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:393101de-7aa5-59c0-b102-c9045db5fdb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:561d8c51-b8b3-519b-9a80-520a7e6d21ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a05b403-9df3-5549-9b93-2eacc4c16cf2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a5de8a3-db60-5db8-aaad-1d20241cf2e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c3742195-dce9-5dda-9333-3432dbc23d84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32b58f45-e140-53c1-8d9b-51a23cb19601",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:29a5e8e8-d653-5468-b533-bdd45d8a92f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ff59d97d-1d1d-5870-85c7-7e54b101a7a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c50288c5-e965-51b3-b7ea-89b81dfa6281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4aeb6595-9d8a-5944-83e2-7d6a55ef0e75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dd266e1d-7042-5505-a31a-85969fb194c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa1097f1-8c7f-51c4-b80e-c9209e389019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e921a99e-5561-5ed5-a69f-7f8ed3f8bdc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f425901-90d1-55e7-aa10-bfbca9d0c9bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28d7dd88-7b34-5f82-9270-dad9cb5719ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fbd2ef68-dfc8-590f-881a-e5a0efe10c7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3b5d897d-7273-5f5c-a990-1b0fcb43422c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.13-tuxcare.1"
    }
  ]
}