{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13237ccc-1bab-5077-9df0-f5855cc1163f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ef1f15f5-d5d0-5912-9a28-f29ab5782552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ee5cc00-1e64-5f82-8afe-64095f0b4605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:48e53466-f0b1-56d6-a136-d9879c6a197f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:42a7fde3-0e1a-5599-b382-b63b921997b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67370b99-be6b-5a33-aff5-efee38402db9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:380b505f-444a-59bf-adcc-f5a78ef87813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ba4654b-ccc1-5937-a23a-3d3d1dc29b22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7b76ddeb-c6f1-5856-bdb3-2dfbbdc4e2ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1465f203-614a-5469-a639-e3c868674cd2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:18058021-20b1-5519-baf3-66a0368760c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f463939c-da84-5fcf-8d6b-3bd6c66006f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3c2e665-b726-5294-a49c-9534ec42a4ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2cff0b54-fa84-5373-87b3-6b465e66152d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c12fee6b-6349-55ca-a5ad-735a7977848d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c904a471-5a71-5f58-bc9c-e08f14c711cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eab5b6eb-211b-5294-848d-b03d5bc00e15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d141ea3-21c3-58c7-a7cc-c2a887d7e12b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00e9466a-177f-5f02-b6be-7ba16951650b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d8fdfd8b-1657-5631-8edf-d52c413b99ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cc593878-93aa-51c7-a01c-c3947e473596",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-web. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bd4c75e-9f35-5874-a840-e0294a12c838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5573feb1-58f0-5770-bb39-49bd1e2a82ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd01fc19-1728-570d-8778-3daff9df9824",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2d143678-5599-5eaa-908c-32b7608974a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:08e7c97c-1ae9-5687-9ca8-d6037b88c1c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6bcc3e4f-b7b2-59c9-8051-dad6350feb65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:183ad750-7c74-5ecd-95e7-21203e96f4bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f4137e4b-826b-59b2-b96d-3897f09e72d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f0b1568c-2abd-594e-8a84-d4a565d13b72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:429d4e68-5add-5714-8433-6c70f4284af8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:275a733f-af60-58be-8dab-89a213574bd8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6df45257-7f91-5b45-9a92-04d2bfdb8c3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d6b4caba-dc1d-5374-a1a2-8573beeeea9b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b8cc8cae-88f0-5d86-a084-ce99e4df987f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:064ffc87-6da3-56b5-9dbb-55bc7ed6fc82",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:affbc77a-fff4-5c17-9bd8-e445f5f803fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:921aa7c5-51e0-5b39-ba0e-926563c68cda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8153601a-01aa-549c-84d9-5396019aee43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:288861f7-87a4-5746-bc65-86175af6aef4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7dbe1222-c099-5b58-a248-1c350e5f8667",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e17dd77-cd37-568b-ab91-5707e09a235f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:83554153-3246-516e-90fd-b0b184640189",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d011ff1-b285-5752-b74e-7cc68451229e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e9a8206-a36f-529a-92a0-37c993717f00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8df7b955-ef56-565b-8609-2ae4f8bbd622",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b3c86e0c-5638-5c97-83e1-fe377df3b85b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bae5971-a8ca-51f0-9995-067f89f34aa3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:89b2cd64-95f4-5bf1-8ed0-6358c07d7ccd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6cd5d091-bea0-536a-ae2a-5e9af8998a5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bc7e299b-5af1-5ca6-94d1-c0a437037de3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1a549d38-e266-5bb4-a605-ccbe6c52f99e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:06822479-5e54-5516-a14b-2c482815198d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1f9651b2-3f48-5534-8bb6-c2f8b875e217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ae58ce0-7aa3-5d02-a08c-085b439797f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ddf6e507-21a1-5b83-b350-694279347fe4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32e2b4d7-daaf-55f1-bdf2-2a00acb11154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c8f296f1-c05f-54cf-a2d7-9273ef7bf6cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:436abe84-7de5-5a6e-b982-883b3eb7a750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:418ffa10-9aa8-576c-bd48-482fb4f39101",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:feacb696-60e6-5ad0-a0ed-84ab1a8c29d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f381bc7f-e686-5e59-bb70-b4aaf955f365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.6-tuxcare.2"
    }
  ]
}