{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7bd8a357-0e4a-527f-ad5e-12d6f75835d3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-context",
      "purl": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:93c75b36-9112-53b7-959c-b529f116f03f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d21a3d27-f08d-50e6-9390-e9d3843742f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7fa5fe4a-2e67-5b4e-ab9e-ee013fcb8b26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f63060f-3a23-5dee-9b6a-c052b5440735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:83c38c44-cc09-5f0a-bc51-ac48fb3d3d22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72ffa6cd-7a3e-5915-af29-b7c8b1fb1eab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0653699-ec5c-5f7c-b2c2-2791b221af46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73ee2c5e-14a6-5e22-8b65-b895de6c2166",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5ed7ef4-b437-59be-97b5-b35c5f78323f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c41a4396-808b-5237-a3dd-1a0dcab9eb8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e3b465e-25a6-5eec-97e5-c806a0a2a7e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1435ea6e-714b-5e69-b04e-c5cd84f04ad6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:363a69ce-2c8a-5f1f-8c84-b4591b24b44e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f51c44e-330b-5de3-b2b5-05ce4777ccee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c797fc7c-8d57-5e44-bf9b-37e22a8bebe1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:194117f5-7209-5332-be42-08badceea0e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e94f3d39-9071-53b9-9785-aed92fc7462d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73880712-5eb5-5d7c-9df1-0501e529a780",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2539a0dd-3423-5038-bbc2-73fcb3e9184e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1f6c28b-5e9d-586e-acb4-a94c362a820b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-context. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:947476cc-6cf6-56de-aac1-6a736859bce6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2409d7d1-b9d5-5e0a-a59b-be812e3506cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:856c57bb-85b9-5b55-9900-2a2e506e1d01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b7e4f81-828a-5abc-922d-1d068ccdfd40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:343f6097-b88a-5cc4-9d8a-86a852a38e9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26fcf0e8-d614-5041-b349-1214e9ed9954",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa66e3f9-cd2d-53a9-b373-510aa3578fe7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ad14e6c-7243-54e2-b480-d03a5ee9080d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:22efa1a5-1bb7-5a42-82c5-04714ed8bc2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89fd3d92-7f18-5a05-a381-2d3d5863af88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:593a3894-e0cf-5bff-a030-5e6335ff2836",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59737718-4096-5a19-85d1-b763faf8a543",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:09293bc4-bc17-5251-8fb0-cc29ee69e28d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:09da25e4-4d78-573a-a00e-670581a676ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2bcd82d-aa5a-5c4f-a557-3fb3d4729ddd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba3684da-4eef-5c22-9037-24400303d5e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9d51f622-145a-5142-912c-3ac4782fe81b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1ce71b1-711b-588d-bcd1-723244e92424",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bc2762cf-bfe9-5280-a244-996091792371",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28c6be5d-c7e6-525b-8741-aa16c4d9a9dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27b6a1b6-4965-5cd7-a7c4-8cf86b6519ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:130e073b-d00f-5720-9a85-771b23298b6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eca841f7-4be5-590a-8594-bd2384a6090a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:840dc486-238b-5625-950d-d3023e696e45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9c67f8d9-86e9-5e14-a4c9-3fa580a140d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5b17acc-cd92-5521-912d-e00fce5e963f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f0acf23-25fe-571d-aa42-c0d0c9c56422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c7dfb9c-2a32-57de-90f8-aa3eae8cb89a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36c2df79-7468-5dc9-b1ef-ae1178063073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e1ad7dc-ddcd-5d59-a4c3-7db0164e5d5b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f81a634e-7ef6-5318-967f-8e72e6deb0db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33799034-b05d-5f00-b9c6-5ad35fcca2b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74886be5-83af-57b2-8d1b-9bf63468a795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:24123111-0d05-5979-b5af-0a312a3fab09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de277087-07d2-5fd4-b470-89fad1c935b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2aa83f06-fe45-5622-9a9b-d3f3371682d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0541c6cf-6504-57e8-b3bb-60ab53b6020a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf420429-59cd-54bc-a9bb-9bec62fb8d6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81cf46bf-cffb-595e-bbd1-9755c6d67948",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:353d2261-0152-5cfd-8ee3-e3e653471383",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e7746188-9aca-5c41-8e94-c311b1ca547e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-context."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-context@5.3.6-tuxcare.1"
    }
  ]
}