{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3e8b1af6-5ce3-59d5-a48e-cc5aafd29c07",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1",
      "version": "5.2.11.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:026a5764-04a2-5779-8758-b9e4a75592c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe1d7a22-2b78-53f3-a681-e4d775e93f31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a29fe1ad-f267-5d6b-b4e5-5c7b5bb35baa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9c5d8b2-b80e-5914-89be-84e55c5caa75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d60b87c-1125-5b95-8e91-61b90ed27b1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5d92eca-7557-5e4a-a569-6c8790826688",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5279b6f8-b835-5526-99d7-cb3a6ee537bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87b84947-921c-59d8-8c6b-bab72635d3ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50a3f8a3-a0e8-5376-ab0e-716ea22ca7f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5420133-afb0-584b-9702-b27b6ded39ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d110d9cb-736c-5030-ad7d-d23193bd7310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5d91bed-fb8f-58b6-a6f7-ab015fe2ea83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f75567f-cf37-517b-be2d-7fe71b22cfba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c6bcd65e-5757-5cca-9b8a-5ee9486949cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:306f093e-ea26-58a8-99b2-2020f6f911c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:97a72e2a-0237-55fa-b9d2-a0e8f7e9e649",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f12616e-81e8-54ad-ac0d-773499121965",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fb1d131-ff95-55c7-9929-77c968147584",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:099c6fc2-bc1f-56cc-b5e2-3f09b8a11c2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c442633-c4da-5006-be0d-1e91c95776e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b36a5c39-2087-5440-9bae-3824bc6f68f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65165efb-1dc0-5091-859d-d01f98f5fec3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f51c4354-e636-5b4e-9221-421742f0a763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:336e39e5-0609-5d19-8c16-199e13c13bf7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:97192e2d-54d2-55e6-a039-f0cab2a416b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ade04e3-52b1-549b-907e-006038649749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c697d9e1-ba2e-58f2-93fd-8e7c3ab94670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6de453a0-945e-5254-a95b-fe05ec98c6e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8d4e50c-a8f2-58be-85eb-27bcddef2a5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc083566-53ca-57a2-9992-edda8a252de7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1da195dd-5c45-5e87-b7fd-8ce79ae4b7f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e1d7c79-2fac-5eb9-902a-53998e4cddff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2990575-090e-54ac-8884-fe8d164482c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85b399a1-3f11-5a23-b56b-fbf3f9f7b136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:126df3bc-b3e0-575e-8aae-6d78d0029d22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:987d14cc-9232-50ea-b2b2-ea9f66334c02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4def4fb2-3af1-5f85-946e-d276cd82954a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7a91504-fcfe-5bcf-9726-8a7586a7d451",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d05804f9-62f2-553d-b435-451bebd5c642",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:447ec66f-6bf5-50e8-94bd-47568143fd85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:085af177-8b28-53cf-bce7-5e2e618b5f4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63550eb2-0567-5560-804a-d7361fdfd58f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3d41e72d-3e97-573a-a509-800dd28f84b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26e3067c-0661-5eb5-845c-ce8c9bd2f0e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d8fcdc8-4b26-53af-ae56-d3851b371055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2a27617-d976-5d85-9156-5aecc312e086",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69b366ee-6a20-5b26-b49d-01b85e6cce99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ed04f3d-4d5e-564d-be37-3dd493a8a2ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da3e5d1c-f3a1-573a-b083-ca2ef4f6210f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ddaee81-db70-5e59-85fc-9684c7144009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4334513f-9cae-551e-98d2-938836bbd9e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89be83aa-505c-599a-9875-877e2545107a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ebbe24c5-fbed-5feb-8cc3-86d65d0f8857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea548e91-a094-5170-b79c-1ae7715134dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0084f466-c5a8-5bb8-a53e-0c5508ed0d0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c105cc1-7cd6-5a04-9a08-01927ef3b257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c3638013-a472-590a-9c7a-72df18887ef4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.11.RELEASE-tuxcare.1"
    }
  ]
}