{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a9660783-be6b-5c43-8610-2f8a5f21eeb6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1",
      "version": "5.2.7.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6a4db7c0-84e8-53b8-9085-87774ccb99f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1eb36e2-b277-5015-92bc-859d25735a99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f301f1fe-bd9d-51a6-829b-6521607a924f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d590189b-5d4e-5a74-b70a-bc7f45bd59de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0348df11-28e8-5485-9d4f-2a50c60b8e63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4350122-0d82-564d-b7b1-4fe33fb37f3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e74abad-b48e-5349-9a53-b40a5131a32d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:21bbb3d8-1797-51e1-98f4-392eeec4ee96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8a50bb3b-179e-52d5-9a02-bd409ed591c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3de87ac0-a5ce-5050-a6cb-5e808dda0bb9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d6982640-03c4-5a71-8f62-f12ab303c551",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8483b97b-52af-5fa5-8230-ce52edc570c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5b1e369-7fcf-564c-ba04-54e4e44770a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b910917c-1cd9-5b04-beea-c46d710acac1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ecc9a0f-59b3-5d60-94fa-b217bb7c7d68",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37ffa952-63c8-5a2c-aae0-59f6b34cbcc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fcb75e4-59ed-53b0-84c7-55e78879e63b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ae4c9fc-9cdf-5f02-a4ac-f0a0b4b6da4a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7576baa5-36ae-5dca-9a55-bffd1ef700fb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf237199-42e6-52af-8ce8-cd675a5caa8d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d037ffe2-7f55-5f30-958c-47a2ce85fd93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d8faaf4-4c27-516e-abcd-cc2196e960d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f0efb347-40bb-595a-8b48-447392c38679",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8da3247-3768-5269-976f-3f82153b2a7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:77d0d033-88c0-5447-8e21-20a73a1f3497",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55918926-1d2b-5468-b5c3-a8bcf543bca8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1858afbc-dcfc-5cbb-9645-095112aafafc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e957af6b-4f0c-5e90-91ae-0c9c480a8602",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:069507bd-5a4c-53fc-b831-ff6ed39a2a5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1225a13b-7e38-5d74-b861-2bc9935724dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f7db0312-0502-5e1f-9a39-0da3d786fa7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94372be2-9f5b-5660-965c-35131ee4d888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63bb9e7d-710d-554c-878f-4a28c74a8c38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d22aa55e-886e-5375-828b-79ae98ff13c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:24911678-febd-5532-9b47-607a9e01864c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:afac0e3d-113f-5e20-8ec2-35b519fc9f1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ab2d777-3b22-57ff-a226-a0a8cc42b25b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f818f953-1900-59e6-be93-e75e88e784d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0fa45c95-7b18-5f35-b4aa-193bf856d62f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da7525b5-86e9-521f-afe1-54d401e0bc41",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7bd9ec44-f05e-5584-ba07-19e8102a5864",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:934efbc6-1784-5cfc-89b0-51c0ca9ecbf5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:efebf391-37af-529d-bdab-7e9af1281b72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b21617b-5dcd-5dac-aeef-f9fc30c0bf7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:784aa0cb-e5da-54a4-9593-06a86ce308d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56c99699-9f9d-5f1a-acf6-014b0f88d300",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ca64e8b3-7484-552f-b34c-c6c343026a91",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53436c68-a7ab-58ed-8e59-9278703093f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1eabf267-187a-5f64-b23e-298546858acb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34e20add-88dc-5981-be23-d9d15896cb0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9c53915-012c-5874-a7df-0e30816ca4a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b63b380-fadf-599b-917e-c6fff78951d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:375cc3f3-0d32-56cd-a75d-5404acd5e43c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f06419bd-f723-5a57-95f4-898901ed0f35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:120db376-1eb8-5c4a-81c1-cbc81cac5cfb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b4d24a8b-381f-5013-a2bb-71a2a0625a31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4abcf0f-d49b-597e-aea8-701ea10c7dcb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc8e9329-c0c2-5f2d-9d68-8406c5b92c2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.1"
    }
  ]
}