{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d0743fc2-56ae-57ff-891a-a0f5dd06f459",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-messaging",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5",
      "version": "5.2.0.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c539fdd2-16f3-5d1c-a6b6-7891e01bf51a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b0044873-a94f-5995-b8f3-ea3f61fe8fd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7e916a82-552a-5b11-af11-65b6ddfd058a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c299f88a-f3d9-5233-bd15-e19d31dbd049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2cd385b2-b185-56a0-9459-3f781bf91d19",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7f43fce1-1e10-5684-9570-e843a1654408",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:198f3ae6-4022-5cdf-a13b-54649390d60a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:db14c013-2ae4-5fd8-8b96-df630b90f26e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b5dd73bb-0784-5031-950e-c815a0332e63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:61d01e85-cfcc-593f-89aa-e009fafcd0e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0349772b-5368-58ee-92f6-4670b2ad4898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0df24ba6-7e28-5b40-9f6c-d21b3990d8f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:615b7a09-df92-58e8-a9c2-0696f6058f0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:15bafdeb-c728-5b39-b034-5f09b2c2353d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2471c4c6-67e1-5414-9ace-52754814b49a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:873a5c53-a732-5571-ad7c-5a56c513a49b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7e6dd2b9-ad3c-5f3e-87ee-db4f79c71f17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a0f9a8af-2eaf-5fdf-81b7-fe096b0ef83a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d387088b-c924-5196-b008-ed8c5d3b595a",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-messaging 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4c695ccf-d28c-56e2-bf39-99efb91f3f50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a4c3e498-9671-58ad-8d5e-ba2c354934a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:876ade50-43d6-54d6-9b89-91a86230f532",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3b4cce31-8040-5b40-b033-33b09280eba2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ca5aa51b-27e5-5771-b71f-ba3ab1aee4d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:89aca009-9749-5d59-9876-54afaa3f245d",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-messaging 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8443d9f4-d0d0-55c2-b96f-f0998bc3eb9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1e2925db-0890-5964-a10e-32247fa5dc5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1434994c-739a-5c44-b19e-2c8cd07db03d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8925a673-2077-52ee-b7fb-be8574710884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8c53a0a7-325c-5be6-a31c-d98a0e712037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2e4e27c9-4c20-5b64-a1a4-17e034b4fec5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1249ba10-0eae-5e10-a333-0455588e8823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:77d7db26-da5c-5b51-ac85-839949eea4ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d7f5f320-21d6-5454-ae2b-bcf608033056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:749727ff-57b6-5364-8d84-c338127e28cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9ad3899e-ef5a-574e-82e0-c995eb892704",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8fb69cf9-7403-5719-8d7c-b9f4ff6948f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:05e24fcb-8564-5e8a-867f-acba8e9cce92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:075f540e-6a77-50ba-987a-110540bbebd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c7854924-b156-527a-9cba-7951b4559924",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e820c7e5-362d-5b39-8d80-2f4ea9ecc96b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8c292eae-8b33-5155-8500-f04bf2776f30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:576de8d3-e43f-5937-bb00-a2f0a4fa4baf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4341a867-ca24-5ad4-889f-c42aedddf5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d5e5785-23ad-5e6e-8a96-f133f632e5e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cfcc6244-6323-5007-94e1-f969033b7754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5e64bab4-362c-5cf7-a137-4047001e0611",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1ff1dd52-1f21-530e-a215-86325b60424e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:39ddaf81-4e59-5913-913d-93f6fefddb65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3d8cc2f9-4375-535d-b845-8f94fd85d489",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:47854b46-6248-5be9-9cc8-0b011b8b760e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1560a5b3-0c56-5a72-a601-260043353995",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bb320e0f-cb3e-5650-9209-301edfe1acff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:20aa180e-c2bc-5a9d-9e83-fc62725517f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5b63b355-6bd5-541c-bc7c-33d6e4047462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dad3b5c4-5a03-50fd-80c1-292b6964a392",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a9e4f916-fb22-527e-8f09-3161048007a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:74ea1977-b330-57f5-b31e-421845e06659",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f71b01ac-7e88-5641-8484-b873ed52b4c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f1c1dc0b-7663-50e7-96b8-f09ec77f0b74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-messaging."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.5"
    }
  ]
}