{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d13f286e-b6b6-527b-a808-2ea2b4a6d5a2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jms",
      "purl": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eeeb8e6b-a8db-5fc3-9f35-45ba84077182",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:60205ccd-b81d-51b6-9977-3c802f83f9d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10ae3534-f40b-5f7b-b9be-aec248b69a2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c6324696-c0a9-5f44-8b86-54214ff2a49a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c022db9-ecfc-5f2e-b4a2-73f2fa905124",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e18c1bd-7356-5560-ae69-bbd3f524e6eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d018dba7-a24f-562c-9369-315f1842b8d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c59c290a-c481-59d9-b99a-0467ea1ae155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d34407e-bb88-5fdf-b6d8-34740b1ff825",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:932e899e-8c26-561a-8717-404c3decb984",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb10ddac-7080-592f-abe2-ce60be3430ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba1d6aff-b901-510a-8e0b-482e0c8abb20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a133091-7904-5d22-8dab-f40cda9bde60",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:00765cfb-6c52-5b78-8596-070200a83e3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65026347-075f-58e1-ad5f-8dc41dfe5f06",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c7c5142b-1863-533f-80ec-fd8871d1b4b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ee8e4e33-65eb-5725-bd3d-5708d319b5f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc9b5ccb-53d5-5133-8f89-8741b8fa8faf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b9b4760e-77f8-52bf-bbde-c8d37abb994f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9eaa6c4d-ce25-541b-88dd-eca84d2417bd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-jms. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0ee4758-6f1c-5ff8-97f3-397122c8d59e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5af3e84c-14c2-5e17-9a11-0b8d84c021d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:207a33af-6c86-5225-bdad-3fed957d95ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a145962-9f01-5d1b-a2ac-ca8b3c1fd6d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:001c1d32-4236-5d00-8995-df26a29f559e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fa14720-6303-5b33-9b24-6d67141f113a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da216065-9116-5eaf-ab7a-6520fad99bff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70a78e8b-e7b0-50ce-a7fc-5231865f5c75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:acf14037-e282-506d-9f41-7f707a174567",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:410323b1-6043-51a0-9e52-ccdfe40d105b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ddb07fa-8913-57ea-939a-a69bbf5b1ccb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eae34555-7016-5784-bfaf-51c5b88c00a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33a238c1-a36d-5597-aa5b-97eb29d4baef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9874aad-1997-51cc-a5b5-8e0a9142171b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ed7e983-7b6a-592d-9d61-557408e8eccd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:037a0ec3-7fe5-5a16-a758-6073f1abb69a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34cad207-066b-5fc4-982b-8836df546a3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b12463d9-017d-5568-9f55-ff8fc19c40b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e64a6d3-426d-5531-822d-00bbc84d73a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2312b06f-dfcb-5b67-82ba-9be51dd666be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e464b6c-8881-5f6e-a026-2b235a7a9e8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e39dd41d-f523-5b16-8558-e7392bc7bbe1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:275002a9-09ae-5a86-9ba6-9a39a8511a31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e682bd7-e2a5-5fb6-baae-cd51bdb33405",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c3fabe5-c918-56c5-b6f7-d0c3f87b46b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4f1b011-e023-5d41-bb0e-05f420ecc40b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c1b25d5-b281-596b-9f9b-b650ada509ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2cf20cba-1916-5e80-94c7-0e83af1fc73f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:afdf8f51-870a-5101-bee4-f11e1976f32e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:19fdd3b6-10d2-51f0-bfab-07e9ed9323fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b243c6c9-2ead-5e74-a8d3-a94ddb1319c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37681d6e-82ef-5d0a-bd9d-c69df587fb28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:325e31f8-6313-573f-bdb7-2e5cce0efaa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb66396e-1524-57db-8151-1931cdf9a81e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a2b48cc-5c7c-5537-849f-0b3d62e835d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c3f40055-e7d1-563c-b8b6-01c77af1106e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dfcd6c81-e3e4-52c8-b5ca-50379f188866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9292aad5-f273-55fc-8bf9-7b2f38862ae2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f435cf55-d98e-5f7d-a9ef-a405244a2a47",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b3ce1ef4-75e3-5e6e-9bed-3b74feb10927",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01756afb-401b-53a5-bd79-3f1cfc9f7a0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@5.3.6-tuxcare.1"
    }
  ]
}