{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:61b611da-3174-5640-be93-ba5197a299f0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1",
      "version": "5.2.11.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e5bac21-57e8-54c2-aecf-968d4cc2d9fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d488c11e-192e-57a3-a246-372c64bd8d4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:787bdd7c-0c57-58fc-b1bf-86eb078d5d63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:228e26b0-173d-555b-b2de-a4733c2bbbee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c43f1bf-8ab9-551f-af9d-b81f254601ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d58eaad3-11a9-5d4c-b99e-7eb5288c4a11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2542d1f4-c8a0-5794-b589-c4098202f85d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b8ce256-307f-5913-92b5-6a83ebe0d6da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ea46dfd-e854-55e1-b928-00ab067bdec6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48b7b621-285d-5d33-8ff1-41d6a1c9c572",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ac2ce0e-5ffd-5a32-9f1a-2467329f1e40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9bcb079c-6ba9-5093-b1a1-c7ac8dee9a8d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c77ba511-e4bf-560a-9175-cf1be03aaadd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9eec704f-5932-5791-b128-aa0c90cf3ce9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc0603f5-18e3-57ec-bb1d-00e2f34f635c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dcd44670-11a3-52ba-99dc-742b2c0ed51d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89cdd22f-78f4-53e1-b601-a2f29bde88fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e30ec28d-e018-56b5-b400-ac31b13a3647",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b10f1a7b-8bb2-5281-9d44-3c308f149784",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a23ad22e-f3b6-5fc4-bd58-77cb68b3f0fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64f214a1-44f8-5b30-837b-3de7dc9ea0af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ececf97-8817-5f4e-b525-0610c3ea414e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:295be5f0-97c8-5317-b393-553f51312790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5f86d697-2a2c-55c0-ad9c-cae37f5b3c75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d80a8eee-1adb-5715-a650-9c991ffe592d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6633af34-2922-5d4f-ac80-2fb5f995a734",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6db0a554-dfa3-5292-b4b4-adc2cfaa9727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a001621-5ec2-5b29-ba4c-aca1b9a58793",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be8d53d9-db27-5255-b928-8fb9f13289ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b49ac82-38f0-5022-b9c9-130fcf82c052",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f0d75a9a-17f9-5655-a6ad-cf787ef1bde2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac0d1f3d-1433-5598-8dda-e7662ad6ce2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0be9f2c-07ce-5e43-88aa-9bd7ae1de5fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:efe394c3-6401-5dfa-87fb-1ad51756dfd2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c36abb9-6d8c-513f-b20f-d811b0c5c09d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0c7fd57-0e34-5a1c-b8d9-10bbf4f3749b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:acdcf86e-0ceb-5203-a10f-5b1eb7caebf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc154a9f-69e5-5ad3-baa4-afcc2d2e8671",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9e703a3-00a0-5285-8413-9d262a3b636e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6f6f4a3c-4117-5bab-a392-2141ae03d91a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e061875e-4e03-51d8-bd15-1c98c58953f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12f46a28-0c8b-5586-8d05-974ebaaf3369",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d8c85bda-7d21-5ecb-b82a-743ccb7ec96e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4487cc7-e699-54ca-81d9-518c1801c732",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae6ec0ce-e599-5c66-9172-1d04747890f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db3374f9-1253-5a65-af1a-9fbbdebcd74e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dca5f4b2-5f82-5a90-9837-7139b4b0cab4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5ac5296-3fc7-52e7-ac1a-eaa5c420db72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2ec0bc4-9bfe-5737-a383-c066c06f23fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e8acb49-9f02-5a63-90e2-37c3bbae67a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d0a3899a-82ba-53b9-8fec-ff6f3f3661b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b3986231-c95b-5c7f-b1fb-24a01b63a4c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c58ccf4-7a37-5a7c-b470-1a52d742ea11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:805c924a-caf8-570f-aea2-cbd688c86f0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:769d470f-c0af-593f-8924-7cda5d3bff39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a893d267-823a-5136-b044-2df50079819a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be317cfb-cd3a-59bb-8199-d532c99f363f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.1"
    }
  ]
}