{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb7d0a17-70e0-5b46-ac68-e173d59639dd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring",
      "purl": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3254a28f-256c-5e8f-a195-609481d034e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b2fc48fe-7f12-541a-9c33-410f55355321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b55facd8-aa69-5c88-a9b9-c808950392e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6e6ae91a-d594-528e-a7e0-3c9dc46addeb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca81139d-3af0-52f6-b113-4c3574506dcb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9641ef2f-dec6-5252-a25f-74e84b1b13a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:444e9942-cac9-5c6c-b1f0-de9d0796bab8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:62af7d01-5f83-55a6-83ce-572233256b55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e9d3af52-a473-50c4-8883-3196862ac312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cbb9491c-0e46-5c9e-829f-cd120355bc95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b36e95eb-12fc-54a2-8fc5-55713bdd061e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:12ea8100-a690-57c2-b3cc-495e92e70905",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32449f06-ee5e-5676-ba34-bf7e458ccc8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9cc39366-d008-5449-9dd7-254dfdf0b7de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d076290e-cc4e-5259-a76e-b6a0d19c6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:48c8d25a-661b-5de9-91a8-ea067b50f22b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5143b0e-d571-574b-81a7-4767466c7a35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97f17759-139b-5330-8d71-9f9afedca728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8df2fddd-bc52-5c9f-a7f6-f05a55989498",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:633265d3-aacf-563b-9ce4-66b05d156cf6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:861cd75e-a7d5-5e67-b5db-5c6f7f893424",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e21ad6a8-4d8a-5bb8-a1a0-bf510cc907ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98e98779-7dd7-5c29-b0af-9b5dfa2a71e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:82a599c4-9540-51c6-8b04-1bae40ed005d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da106dda-04dd-524e-a246-b42df1ebbd43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8f42693f-945b-534d-8e69-d1d74ecc6d8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a19237a3-f829-5c20-bc91-f8edb56b0bb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:33a7ab07-dcd7-5d8b-b8ec-fadfb22c03bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3237753f-d973-5126-b6c8-601e6ce5bea9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b7771a29-cf49-541e-b2fd-6969fd8eecd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5b7bce8b-4001-50fb-bbf4-f4b19a57098a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7c8e208b-c0b2-5413-92fc-4a135595bb88",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc1ef14a-71a0-541f-bf29-33d7dcb9fcb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:11aa96e8-9ed5-5089-b2b1-4b1175707e73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:01180d50-82ea-5412-a17c-88b00042c59d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0305607a-dc3e-5f88-9524-d24bd223af31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7613fc8-11a2-59d2-863b-e20ebf59e5f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:49c5e921-e545-53a5-87ed-d2cd83f4578b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2031535-d013-54a1-988b-6d4f17fb3158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8202315-48d5-5277-aec5-9b5daad05243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d4a26966-426e-5f31-b7dd-0de696eacb09",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b2b6e794-c3d7-5a66-89bb-c430adc10cc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f55a8968-c4b0-5b36-89da-2eaf9b378168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d56515bc-d035-5875-928b-077c93e4f2af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17d7dc8f-bceb-5137-b720-c6099b4d32d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fc0a7367-cf0d-538e-9fe9-0067acbca626",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d01c37d1-c2c1-5778-b4d3-773a0ab8ce17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8bc5ce1c-fec6-596d-88ba-bc2b4dfb10f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:800256cc-6c99-5752-a84d-738d7ce84e24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:814aebc5-5fa0-5f0e-b4a1-17f28da31e3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e88f05dd-d1c3-56d4-b423-4d77bf19ba85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ba41d3d4-63a0-5432-9d9b-2444acdf6f61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dbda1e2b-cf01-5466-b57a-1abe73fe5210",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9b846d83-a070-55b8-a091-1affd39dd7ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74ba8d0d-5433-5d54-b565-6215bcbee5c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3823da37-237a-511a-80e8-93b769594198",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2159836d-f2a7-5a16-8b13-0859065a4ac1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a241bf4c-7937-5fc2-b931-1ca48106895e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:625fa95f-94dd-5166-9c84-b16ff0f2998a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6e236271-c6dd-5884-b15c-2d9c32707ab6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:95d3396e-96b5-53cc-b642-e535733ab5d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.6-tuxcare.2"
    }
  ]
}