{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4a0825dc-1c4e-5366-9279-67cb4f719285",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-tx",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:317bfb0b-b7ad-5822-94fc-1d582448347a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3fce285-861c-5e11-8bc1-821fc8a79a15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a208ab9-10e2-5a77-9f4b-e3ddbdde2a61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4096c7bb-c4b2-5459-ab83-70041f7c1e44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:efe8aa7f-ee89-5a07-92bd-b4c9ba169075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71f301f4-7973-586f-a4e1-00ad4435d3c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1f12dbfa-2d61-5cdd-b96a-9d25bc42dc03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56438d4c-3bb9-5113-a661-a6cb01267d07",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65539df0-a680-53c3-a74c-c17b223e12bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5ce3a5b-ddf2-57fc-8e78-6a083be108cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5b7e24d-53b3-5a4a-9e12-11ffce3ee4f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:21688ba0-08fe-57c7-949f-1547ecce70b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cac2af2d-efbf-5255-b0cd-c23340fb7463",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a6559fc-53c9-5953-aa3f-074b1ebe3b45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:673d764d-a686-582d-a620-ff4dd5c68e75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ec1e717-6ccc-579d-9355-4c260fa58099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5021cca7-8869-5eed-ac5a-1b92863a0ba6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ce1086ed-f7b7-5209-99a6-9394c81c5a96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e20fa4b-01a9-5ed9-ad9a-eaf8dc0bbd22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:768bc0cd-c7ad-5569-a20d-59286e1b408b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d829ad35-8f4d-5b17-b85b-a63bfd21736e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f712a251-df8b-5536-85e5-4e1fb94d397b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:004e3341-117d-5c57-b120-621dda06cb84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cb67bdb1-8962-57a4-848c-1cf73ac47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38d8eebb-bd34-5587-90c6-ac3e8ee7b085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e0fc819-ed9f-5d94-8387-d53bd28a3745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c34e87b-b80d-5ad1-811f-6e19e12d3158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78f492ac-9d5b-5f54-a1e3-7c999aa470ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36ac17f3-6f7a-5274-874d-ff21381faa9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:98e2021e-ae03-56f3-b026-0a7b7f0c8031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8e26c8f-e7fb-5efe-acef-fd6257627462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:782a33a2-aedd-53ed-84b6-16da247eb6c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f817c8d2-fde8-5dd4-b20b-551621df5a62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67f9d9cc-d654-521c-88f8-e3b3e4b07fb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73ebce7a-13f6-5714-b6a8-733ffb34c753",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8329c496-8a37-5218-a700-1434f35cafbc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a609e01-3b1a-5434-90ed-65a462cda0b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f2a361b-2827-5361-ac28-e06b8da8d0c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ff1ca14-cc1d-5cd9-8008-816287c7f9c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ffeaec94-0367-5f3a-b640-e2ff5f19b41b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:93633c9a-6fbf-50bc-8fb3-a4671e4f26ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b3615fc-b8c8-5f8f-9643-fa31c4b97ef0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:579f30b9-15d6-57dd-b813-da05639b7c0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:add5d236-0bbf-5e2b-b0be-6e13f6ee98e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63c1d063-9178-5cc1-9b32-4cbfab422eba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0158402-07d7-58e9-a6c6-042ece98a833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1886488-a4af-558c-899e-5f5bb8449c82",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e87194a3-4967-5c2d-8c7d-c3a2479abda4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4b4918c-755f-5d1f-ae95-3ee558c5a916",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:759592ce-455d-5dae-9582-1169a6fe97f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1308794-a990-5ebb-8104-432785f741e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:798909eb-53b4-5609-ac1e-a4fd0d9c13a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:479f7fb7-7236-5748-8232-38f5fd024bb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a825cb45-ab7e-5316-9627-cb3278a59ca9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a13426d4-4c06-5e68-81dd-d0323e1e2b85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e28e605-6b5e-53f3-bc59-fb90abf1b354",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f517cf2-d34a-5e0f-a415-2a5ab2ce63a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4cebd753-d108-50eb-87e9-b4a29e156140",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e20f4308-fe21-5a6e-baac-de2bafcef936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e639574-b18c-5885-9271-02aac0ad6121",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f63b4e7-3fc0-526e-b6cd-253d4f451a92",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-tx."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.6-tuxcare.1"
    }
  ]
}