{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ce690794-a9f2-54a7-9d0a-256507c0788f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1",
      "version": "5.3.33-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b42cf39-9ee9-507b-91c4-ca3e949e9cf2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3db3b181-62f6-59c2-8d1a-960a463624ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ebc138fc-2a80-5a45-9233-e25d39ab2780",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:943eded6-e35e-5b34-b498-61359cd5ef0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75177f0c-153c-5864-b3f1-718e3205933d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:07208759-5111-56b9-9b9f-8ce28f4ec4e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4d79e40-a07d-5969-86d2-075efca6305b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f6e8c3e-7899-5cf0-9b49-cf58c30a059d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e987859-c23b-5c61-9ade-d3b69fc234c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e370fa8f-195d-59e7-9221-b710adbfee5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:295c4328-0b9c-570c-b7e0-f9b6113eb3ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1fbd9b41-2b21-5416-8567-929da3a3a392",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3341b4bb-0305-5f58-ac30-e8b2e310d7cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:edee2005-a5c8-534c-b40a-79bcf50fd939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:359b7c8a-410a-5a28-b996-dc4beca84cb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1757e3e-72e7-5030-b90f-5ac75f8bd1f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f306332-8082-5680-8cf2-31b83e7b69eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d46153ef-4aab-5000-9090-51def53db25e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:25adbed6-8e30-57bc-a40d-a6ae3787158d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d62fe48-e0f4-556f-aaf1-1e3e586ac699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5687e693-2910-5d1c-8821-5b8f8906c458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72eb5c37-7aca-59ea-bb96-8984cfa6bb97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0528ece6-2708-50bc-9152-b6b42e82c467",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d6afb3c-d2a9-5fe5-895d-f61c9b166dc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f749134-9d6a-5c74-bc3e-bfb804374d3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63147a2b-c7c8-5240-b4b1-f24486ee916b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74667638-c387-546d-9b86-84603bb1160a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44101289-97ef-5464-b744-153a498290dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec95dc85-09f2-5b03-9eda-855b4487cb2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:60812230-4b15-51d7-9653-04c009c483ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d951d013-7ed2-5611-8d5b-3aa1e1bda24d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:053b7c39-bd2c-508f-8886-ea176d7976d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c72bf0dc-e3c0-5b5c-a6f1-f749e2e5c5ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6bc44db-1890-50b9-9064-cbda1373f9b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72906a90-c6c3-5227-9a8c-c70c396299e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:25d8fb0c-afc5-57f3-bc7c-542d42c57586",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a74c4af2-26a7-57bd-b309-209678d916fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8d79eda-0601-5610-b404-c62001bd38d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9601378-417f-589c-bdca-6911cd440c87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76319a99-24b8-5621-b903-8bbf8cee1f5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a88f5d4c-c91e-5dd7-b1bb-718fb1bb37e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c07b2936-a472-5549-907c-4253a20bf723",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8857875e-8900-57a1-9872-70aeda4416a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52d5a201-a917-502a-b6c1-d2b64278178d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82a00a0b-6080-5f24-a640-463544029692",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad4c574d-446a-5b74-bec1-0a610e319080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5202c718-ede5-5145-b80a-820708b451f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d839b51b-d770-57b1-9301-74df3d685657",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.33-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.1"
    }
  ]
}