{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3026e306-4bac-5f82-be22-1c702bdd0038",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-aop",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab9d7789-2dd7-5d83-acae-dae4349e0f1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e053c41-a9c5-51fe-97b5-53e97bfe601e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf273832-5770-5f74-b93b-a782d655a97f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b1fc629a-242e-59e9-bdb4-bf3da824ae3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52cff19e-470b-53aa-8ebf-9b26edd178a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:25142dc1-fe56-5e5a-a995-59b6aafe4d55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8f1d1b5-c613-5fdd-a8a4-dcba9c1ea723",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:195761e6-bd59-5981-b405-413c5cfb82c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e763960-51f9-54fe-92fd-650835d6987d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8d79b0a-3f77-5f4d-8ebc-da69086e13ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6224b486-37c9-5e54-9d17-f71d8120e3bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:42991780-004b-590a-94a7-0bfb79d1b94d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c246b3fc-d69e-5dc2-b6f8-22cd97e63410",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4253798f-1702-5ecc-bb08-ec03b9fa098d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:df4d87dd-dd9a-5539-926e-5acc2fd04da2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:24f0b49a-9ddb-5ca1-9353-d3a402db53f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79a82ac2-62bd-5882-b137-5b30be695756",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:689f9808-9bfd-56a3-9c4b-d4c33af37f55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a4c6f25-589d-5846-a631-23b1c459753b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:538882e6-9820-5331-a18b-bb6ce62aafb6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-aop. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:847d6a63-8603-5980-950b-fda414a90996",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cab2bed3-9871-53aa-ac27-4cb41461e187",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8cf55a80-b168-5aa2-9de9-ce4b6f8034d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2e09858-4d8a-5e57-9835-fa6eebde331d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:886dc938-9404-5fc1-a4a1-91acea76e045",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8f6c5eb-7cb8-5bc1-a3cd-e9a462c89f3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5c4fb989-96d3-5b66-b5c4-3f460ddd23a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28f16167-ca89-5f32-a614-91bf37a05e44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fdb4d5c5-7999-5ba5-aab8-d862ddaf930d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:77367681-bd13-51bb-992b-5f40a53a663f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de710934-7a13-5fcd-bcd3-5ca10f7d53a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc068eb1-a256-5223-aeb7-390a3ee99fcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3841420-b314-59ee-a578-70da388f6f8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:58112966-71b1-5ba5-ac61-bcaf3bec07ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:037d58bc-b23f-5054-ae7c-26a5a9771252",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a647513-4207-59a7-95a7-0245e99b5fcd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a73f113-73e6-50f7-bc65-0fc74a3111a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b453eb1a-8566-587c-882b-d9e379977d94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e89ccd5-78ed-5eff-876d-03a09204e826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b185c2fe-9af2-526a-ab2c-76ffd588b884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e43263c-4c6b-5e00-956c-89b574d2ab39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc8d474a-8208-5c96-927d-c3cd922286dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ff6729c-86c4-563f-8686-e12e29bf30b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:305f021b-f7a1-5a95-9c59-6bae489510e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d247bb53-5aac-5733-bb7c-37b14062afec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fbd0f1e5-268a-5f5a-9fa4-e1c07ef9553e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc0e5e2b-0f48-57fd-8eb3-75a613548522",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc58745d-786a-57c1-87bc-c31c0f34b7ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1bd81007-3cfa-51d7-9e98-a4894c1c4a86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dea605a0-ef7c-502f-bfbb-c07f83cb72e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3df47208-99c5-58e3-8169-bf4b0eba616e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b9a4383-b1be-5a5d-a564-a7b59b4dfad6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9eae069c-27e5-5201-82f7-ba1d285fcf17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c465d388-519a-5a67-b2e1-36be5ceb42de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:659870d0-cf4b-5d3a-b92d-dfd213a26c8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ce177f6-2710-58d5-b51a-c7a92ca522e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56c953ac-f1dc-5456-aa25-1356a5283c79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:566948db-d0fe-5bd5-a6f7-2161622156d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:819d0481-445d-52d5-9edc-eca9ab358ff6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80eaf8fe-f33e-5747-98f1-fa55160362fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:11129c40-b6d6-5d3f-ad23-cda0a1a0702c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-aop."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.1"
    }
  ]
}