{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bfe0d4d9-b1c9-5080-841b-5de9ecaf33a8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1",
      "version": "5.3.19-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:857e950c-68c0-5260-be15-2cbf3594ecb8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3a3f3467-1489-5013-8576-9da48e9e2e0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5248dfaa-aaed-53ff-86fe-423670abfd57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ee16ceb-7dc3-5084-97c1-2b4f3d133051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:057d9398-f37e-5d13-8233-5315a4806b52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16d7be93-4ade-53f4-87bf-9318f8fd68af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18a2daba-2602-5e63-9907-80d8473d93cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b23ebc3-692f-59c1-8382-c63c8465db8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27e92a19-5e40-5c12-acc0-11ffe46a981d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f62307d9-3099-56f6-adba-7986bf6d270a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70fb8036-9c07-5753-8623-8c5614ce0cb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:981b1e70-d8c4-5878-a5ec-56ebdb2bd434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69b54003-195e-5172-abf4-32b0ec92d95f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:029671d1-8bad-52d8-872b-03fc53c3bac3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d97f0999-3084-5d34-b85d-f385d0157b69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b1b83740-8ab0-5ab4-848c-5d90a5704d2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9b59f12-c0ff-51d8-953e-68c076a58cd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:779912e4-a069-574d-a04e-6f828f24572c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d227566-e2c8-54f3-96fa-ec2da240b885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc52aec0-7501-50bb-ab41-bf42c38771ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d1a2b58-6302-58ed-bc77-d212ecb89dee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:712cffd8-5621-5450-8772-6a401c731549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ddfc9769-675f-5429-ab13-8a58d34a59a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:14037cfe-20d2-5942-8798-7a25e7320161",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c11abb94-42e3-52de-ba67-c853766efa66",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a7da0bb-2655-5a31-b85c-6264ff83ac91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:11842b2e-447f-5a39-8a8e-24ad91d4b17f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0962c0b8-0eb8-5352-8d40-0ba369bae405",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc2f1372-28f0-5333-a2d5-3aafb4817bca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:647ccfe8-39cc-5a6e-a694-f3bb3ffe16f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6acc2288-339d-5903-9daf-946017bc4db3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f0006957-d9d5-5c1f-8e06-349f810c1d2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:777e8342-9930-54e3-93d5-f36f3c0d3b2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c1e12ea-11d6-5d1e-ba39-85a311e3fbc5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.19-tuxcare.1 of org.springframework:spring-web. not_affected \u2014 Spring Framework 5.3.19 is not affected by CVE-2026-41847. The vulnerability (filter parameter shadowing in Kotlin Router DSL) was fixed upstream in April 2021 by contributor shindong.lee@riiid.co (commit 07ba95739b). This fix was included in Spring 5.3.19 when it was released in April 2022, over a year after the fix. TuxCare onboarded the already-fixed upstream version in September 2026. Both ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:edbbe180-aa0f-5f3d-869d-76d1c6269ad5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f246d3ed-ab33-5940-9b17-ffca66acf745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:097cda0b-cdd5-5884-8d55-8778e241e72e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cfcf23eb-6508-52c6-9c4b-709cf0e7e0e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ae04ac0-8863-5153-bd71-5e3ba7d728b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34bb738a-49e9-5910-ad61-6406a305f2a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba732707-9c09-5db7-8139-9508fca83ade",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3b6fcb27-7a3b-5a2e-ac5d-edd6f5d8d51f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd99fae8-0fd5-5d69-abc8-d1dbfb4ca0a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:222edb44-7bc4-5473-8b64-125fa692f1b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:095f5255-c778-5072-9aff-9ece39df8866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40d70996-c15b-5bc1-acbc-b42b23b51c82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b3f30255-cf83-58de-9ac4-40415a69328a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67246c51-be90-5c21-a6f2-f6e6ae201f86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:400bfb4e-2aaf-50a6-9458-692044dc1aa0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ba11092-7b68-567c-8e4d-f8b3bb5ba83d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:343355a5-3d7e-55ea-8e75-25d9ad1b5be0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5aa220c-0c79-5c35-b5f6-2fe1e68a98e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be68a619-5521-5ab4-872a-11f1b87c0016",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5ca980d-d34e-5547-8edf-330d89a9b9c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:929256a2-4aae-54ce-a372-0233b8e1ed14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.19-tuxcare.1"
    }
  ]
}