{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2de412ad-8ac6-580d-a4bf-80bc5295e0ac",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c173c07-70ad-58d8-9ded-5713badb6ffc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b23022d-25ff-5fea-816c-de0f11a059dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d64f900c-1e56-55fb-82de-dc5ba57d415d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8feddc4a-565d-5531-b950-f6b37d613010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b4bc865b-9960-5e84-ab46-0ac10c3cc038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8c10d36-701e-5b60-8884-feda760752ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b0b9c8a-c882-5494-998a-1700e31fd0f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3c5e0b1f-c474-55c4-9cc1-080bd97ce104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57cbb3dc-4063-53cf-864b-413ff651d6ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:95ee88be-a28d-56be-b46c-081fe450f609",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57a67fa0-c0d6-57cd-b2ff-7d296ccb5da3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6c4821c-1f77-59ba-8332-7b09915886d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86e2a341-2ec1-5367-9776-94cbe404e03e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bda67ff1-f1a6-535a-8947-7492aaf51592",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c379f38d-a407-56d9-92bf-453cebbea741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:97f4eea5-634d-5947-9866-3ae792ee886c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57044b16-05fa-5d3b-aba8-e0c04774bc6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ce32826f-8d1c-5c1b-876a-16aeaf252c3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d96ff009-5fb8-55b6-8003-068e972f4c77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62ccacce-37ba-5c15-8287-63fc55dacad1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33b3a438-fe1e-5ca1-80f5-34ac0e085148",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12066d3a-8679-5314-9c6e-79741e115861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:00acb311-51d1-5d71-9ad5-d5ca2e4bab76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c69c92a5-9dda-5912-83f0-e236cd39b439",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a6f830c-b19f-5343-a015-8f05dfc2f8fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e254f6e-46f7-56e2-b334-a7842f7c1ae5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc7aa35d-c29f-5285-840e-43de4d7d2796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d3805a7-54ac-524a-9434-e033fb626d21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:13cdd02e-8e38-58ea-9c74-744e95724f3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36fc0d02-9281-55b1-8dc7-deecf48b7f8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:236a1e81-1961-5bfa-88a2-4f2fc66e7789",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a8e86fe5-cc81-53c3-81ec-692d2e9cff7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32e16364-d1e5-5338-92f6-9c8a332bdbd5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:88cb93f3-7b72-5ff6-977c-2b2ceedd5e89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dcf0d81e-ae3c-5dec-8303-b1709e9f6c10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ccd81825-53ba-50b5-a191-603efc228443",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52f3e249-fb13-5651-a995-64fff25190a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2426f00-3a4c-5f4d-b822-498b2c1cc056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0fd22bd9-ae97-5227-b02a-cf1f7fb159d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a7b2c20e-4008-5fc4-b606-9e005ef67a41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3be9f82d-beee-5300-9806-308170a85c1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b55e3e27-19f8-551f-abdd-cabb15d8d3e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:980e3120-244a-5437-89df-83d69b459277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a22cd0d-7cf7-5cdc-8bec-e9abb2d67beb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d32eae0-e85d-5839-85de-9b527829ab43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32df5335-23f0-5e04-8c7b-e0d9876124bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4608377a-ab83-5fdf-897c-ef0cff768503",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27e9288a-5ba2-56aa-898e-aca7dd0bea55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ff097866-6832-5840-bfe0-c33bfc14ae34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62c242af-4b0d-5ab3-bbc8-d80dec7085bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1f88cd1f-521b-5a65-a1b5-73f8a6c4480b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1304257b-d8db-57ea-95cd-35a65ecc90b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dee95a05-243a-5ec2-9e79-f51c0d3f8692",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac1ecc29-e557-52af-8102-f5fe754ac51a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fc483ca-153a-58c2-be9d-2232653edc34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b0088a2a-97be-5db3-94c3-4479878e56ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:456618da-0c42-596b-883d-6e919d737797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30a1680a-10c6-549e-b3a3-89e16d73c3ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6db1046-c4ed-512c-acdb-9a5e86166f86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae3163ad-e15e-5614-9034-17fb5c00cd65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65689445-39b4-505b-8854-817eb1f5fc01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.6-tuxcare.1"
    }
  ]
}