{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c41691b9-ee18-5de1-8fb4-d1d1ecf757cb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5",
      "version": "5.2.0.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e29537e8-5bad-53c3-907d-d8a0d469874d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a290f4b7-2efe-5bf5-8b3c-5333aff5734d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:98d97fd3-0e3c-5bc9-a8f2-3e426ef09a47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f2d97007-4fdf-5584-8014-1617521dd4b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:858192b3-0637-5ed5-b807-b9041139cded",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84facdf8-cece-5d05-892b-bdb2926d7b96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c6cf0f47-5fe8-50c1-9bf5-14ad21920d48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f2665a48-e5d0-58b4-bcce-75ae04afb4d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f1607f3d-636f-544d-a01c-8606b24c894b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:276602b0-5447-59ce-a7c4-c8ba0a81d46f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:274d697c-fb9e-552b-8035-11ada712ea91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e8267ce8-9fe4-56cc-ac76-01ac0c3bbe99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:206b4b1b-4ad3-5f7e-830d-0632739f1f6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3202d752-74a1-5862-9401-a6941b02c7e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fdc1ee9e-13e5-5150-b9db-2d1fd07b41af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:63c53703-2460-5e2c-8b55-7ae795e0fab3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9f43a002-67fe-571a-b590-ff2aebafb36b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:53d60663-25cd-5fde-b36f-fdb57bfeda30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:36f1b12b-4ff5-5e47-acf8-59bed8f2d22c",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webmvc 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e3f2cfd2-329b-511e-9ffc-a17f2f46e515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ff60c9a-6bb2-541a-941d-9161217828c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:03ea10f9-a281-511d-8346-da3b1a0f20a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e3232473-47d2-5384-b518-aeeb30b76d28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cc5b8a98-62c5-5077-943c-cf886b519c2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3bb740c9-a378-5f84-b185-d0978b099b15",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-webmvc 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c6882b2a-4746-55a9-b714-eaa7e3c9141b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a34557eb-9b0b-5738-b26a-11e6e4522dd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2d00d4da-85cf-59ef-bde2-2e00cd96c896",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8e40e425-41da-5d41-b631-eb01fb73d6d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cd6cc39b-e74b-56f1-8fcc-5ac586d533c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8509bb10-62f2-52b5-8484-c052991d036e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:290aff7f-c3ca-5564-8d6b-35d895ff7c7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d024e9e2-6827-588d-b363-523ab9004e9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9dd57548-57d3-51aa-a67c-b5f3693001ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:642ab6ef-d4e1-59f1-8c9c-51491dcb06c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:59cd4a62-0b6f-56fb-8f74-3b535afbde1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7fefe88a-f4c6-53c9-b1a0-d8c751e75c1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1ff53104-bc5c-5bec-98b9-23b27378f245",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1101cccf-f8f9-5cfb-8c0e-6e90e4f6afac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ce264283-d529-5d5a-b291-445c8b05fc6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f401abd5-d1cb-515e-abf4-75fcf51a1586",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a1340e03-d469-5027-a703-690340a22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:98ad909d-baa7-540f-b9e9-478c9a7ba195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:128eb002-4a94-57da-af4a-2327e289f55c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5ad25daf-0f3d-53bf-922a-d8513b3b2243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7785da04-eb97-5a15-ab67-904abfaf1171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d0fe0efa-bca5-5088-82fc-8e182262768d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cf897400-e75b-5f85-b360-e4c08328fde5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e40c0ebd-96b3-5d40-b48f-88a9316e4b59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8a775fb9-da0d-5251-aeb0-b66c9d04191d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c6d53272-4a40-597b-9ea7-9cc418b632af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d3f03f56-119c-5ce7-97ce-638d4f1026de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ffbc54bc-9cc3-5b8e-aecf-a2389e0c613e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a6e71d24-0122-57e2-b797-65719b714cf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ff8ab937-c440-59a6-8d1c-7144e2d847bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0fbf15c2-6971-5184-bf65-2fb11c5d1a9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bcc08d7a-d41f-5a34-bfac-e6c50f4cb085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b90e6380-ba0d-599f-b10f-bc7d39aa9c63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:807d9172-b2b1-5e59-a4d9-2022619d2623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:65d53f11-4277-5387-9a7e-d7509338a4d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.5"
    }
  ]
}