{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5f3ff285-6f78-5a1b-b8a9-3032cee8f5ad",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1",
      "version": "5.2.7.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d0d3127-084c-56ba-b455-354401eedba3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b92fe252-5213-5792-bf61-f323594e4dd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c5030bd-7bb0-5dc7-adc3-fd25fc35087c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b2c0ce9-b16e-5d9f-9888-3f66c2e12c23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4af349bd-2608-593d-9fd3-6258a16491e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12a2e385-b752-5681-986e-478e0cd55c6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36a8471a-aca2-573e-9ac1-eba17ac54ad1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ac9ca5c-bab5-5080-97ff-44dd16d0addb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cb69d931-c9aa-5e38-96c0-eda78d5d8246",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:331ad500-748d-5788-832c-f0f17a648ce2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82ac17f1-75ea-5e5f-8936-16b85a303451",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:963f510f-24b7-5a7b-9b87-284d1c8d4659",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4695e46-a0a7-5e41-a947-002cb3397c91",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e39dd8bf-06d2-562b-a024-5f23f7ad0bf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c0759ee-7324-5b92-9757-6016443a1f54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec0ecd46-5f47-5181-97fd-410b56f24a9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85ce0a3d-4d84-5366-b8b8-8179571397a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4650e4ee-597f-561a-9aa1-6088815c97d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e9de73d-f70e-51cb-96cb-bf3f3e9e567d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0adccc11-86fb-5053-9ba7-5f7a11f4e0db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:caee78ea-e0cd-51ca-8f9b-1b083f54416c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2def321a-242f-50fc-b9c5-1902d8a56823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28689ac9-8d8b-5547-9c93-54823d84cf6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57aba2c5-c301-5968-afd8-4d452f84d122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:92e1d8ef-e27a-5ef9-bcb4-42f584dbaec4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74510177-355f-5b8d-ada7-2278980535b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:68e09bc2-e56b-5e6d-ab7e-df81dd9d5fad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f00cabdf-fce6-5147-b82d-a0db595405bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dee3f18d-beb3-5587-9b1b-a269f43a5d81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8638641-17be-5064-a10a-37691b3dfa65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae09a848-9440-5d71-b8a0-1a728a7cb51a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db45b0a5-0ed1-5e7e-8126-3d19f2af684b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f5dc8be4-e980-5f22-af56-eec3eb6f45e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a17fe66-f91d-5930-bfde-9a41c2dff722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb370ffb-8dc1-5ee6-9902-4b30c9698cf4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f399cf7-4bed-5e5c-a212-dcc79fdf9779",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a455fe3-c139-5ad9-aa53-b28915906dea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69d754cd-ccb9-5993-a86c-f73d0a666e79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6585fbf4-f2f3-5e95-bc6b-7984dac3d03b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:96de9817-eb3a-5002-9ca4-78fb581b6d7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a72f1250-f3de-5e75-b16b-952385fcb4d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:664ac813-9a5d-5468-a7c8-60028865abef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5d2f5be-a078-51ae-9ec9-6b0176d553f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a91201f-bb22-5512-8feb-14a69e8c64de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4371f5c2-3971-56e5-ab38-0133cd0c345e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d377c0e-f3f2-53f3-8437-ee6d03a52302",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:41a5cab2-1d97-51ac-a7e0-94d7c6cd6b02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c17a1872-c15b-5f86-b935-ff8906600cf0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a79f0721-6cf0-5df9-843f-414c19d2676d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:caced7ca-647a-5002-a7fa-048ce6402eec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e4742ae-d74b-5b4f-b5db-515ac40c4639",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:00cbdfa8-b4e9-56a3-9283-d4c07c62ad5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f11d9245-595d-583c-826c-d76af8ba780c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99c41011-80a6-58db-b54b-ad459b4859cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5cb03f88-49ac-5789-a53c-064f72a02e2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e3fa4dd-e1ba-507a-8f6a-fcdc1ad01388",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e67ff1f2-0068-5a91-b3c2-b97b8e8e3b62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38bb1b12-61d6-55a7-84a4-ffcb30b11ce8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.7.RELEASE-tuxcare.1"
    }
  ]
}