{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:26cf8e7b-aa6c-5de6-b609-a792b61a2803",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1",
      "version": "5.3.20-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9cd9e07-ffca-57b0-a5d3-ced4cf0ee668",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57d2b4f5-1e83-50be-832f-24dd94712038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:111e63d0-f1b5-5a11-9e1f-cb65aecc4b0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26dd00fa-8198-5dd4-981c-690e0b0f5d50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10331ff6-1de1-587b-adac-4922d56d4a21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6229faac-135f-59da-9372-0c3d1b798207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ed98fad-7657-59e6-98a7-a969c14bb9b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3f9fc539-cc19-565d-8f1e-0b48594d356e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5869d43d-01ab-5068-bba5-61ccb9b2159c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:19955c38-bc7e-5a39-b1b8-5fe2781e3000",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3d6f8bc-799f-5358-8609-d51d3fd06568",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3cb61a4b-5138-5cf0-9624-f90d38c0a9b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:068bb2d5-f625-5f76-ae3c-e7b11b58f5f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5acb85ce-8e96-5f89-9d37-93fb3e8d0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:90313197-4917-5aa2-883e-bf5968f1691c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc5fcd69-82ab-5044-8565-d4015f9d48a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a3aaf92-9399-5c17-95e9-422b3a9b9f98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b71375f1-825f-5afd-8e2b-d8062fc5e52e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:815ae425-cfcc-5fc6-a6d3-6224dcf738fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a7ea33d1-69cd-5d54-a344-392ebf9f34bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed60d60c-3e00-5c00-9142-fac0321f3db9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:013f101e-c027-5f9a-98c8-1440812a59de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ceee1c1c-578d-5d42-b8b9-66d4ae8190ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:03e6a96a-0db7-5082-ae2e-0ef9750a10ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec8f0f17-0302-5427-8573-46e4d8d783dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e773b75-ff7c-52d7-aa2f-79df1a175506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5c96f1e6-522d-5f6a-a34d-1061eae7ef5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54f16441-20dc-5ad2-b176-6b0682d56424",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c561499-9614-5515-b657-66a4c0ad2a8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de72503d-87d1-5805-bb33-65e6dd0ea0e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:500bb0ff-fdea-54db-8c92-12ebb56cb152",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f45a355b-8f82-52fc-902f-7df6f0fe1f67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f7adf16-cbc7-5ec8-8a4f-9310423305dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10464ef5-782b-55a0-8f95-39a53355ef03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b338a413-5d90-51af-838c-eec3ae05b5a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b71434d4-d5e8-58ca-b78a-e810b23c6365",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:befed6be-5f39-5950-a361-e4c975d6985c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16de85ad-5525-522f-a0c6-a3a52ce5f475",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6119784a-9bad-53c8-8c21-07b7208c8bc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:423c0f9a-fec7-571f-9fad-4cd7ce88acfd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec0e3390-f940-5ddc-b26f-7a00be5e1d12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ce8f7b3e-e374-5eaf-ab03-09ca65119f82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c7d7db89-64a0-5a8e-995d-b32b187bc469",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a141b1af-9847-5f82-b517-94df1297f623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be26681c-1f90-525c-ad82-5df2107860a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b7ceaff-eaaa-5918-aa9d-469f787a4c96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c950db99-ef91-5e17-abbb-fb2326330b13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e01d6d7-e43f-5f09-8468-d82c69769626",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4e83ea1-3dc0-57eb-932f-267a04b51b76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cefd58be-cde0-5226-91b5-d2146ca8d727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02e407d8-d4c6-5dd1-b80c-dd14319e47b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2346290-e537-5a62-a5d5-3f232a0896a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fcd959d9-03bb-5c4f-a6e1-532950dd715b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.1 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.1"
    }
  ]
}