{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:97902776-5422-52e8-8264-15153426f286",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring",
      "purl": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1",
      "version": "5.2.11.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0beeb2e6-cbb0-5350-be9c-04152687aeda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ba5383d-ffb5-5b80-a414-c9b41d9f05e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b34a728f-aada-537b-a504-baeb795bcb03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e1b453b4-4b13-50fd-8b12-3729c126d55c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e09a066d-40c5-53a4-ac7c-700e08910064",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76049221-faba-5111-b705-b1aeab2ae26c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc12014e-1414-5b05-99da-61980f93d13e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86149b75-df14-543c-a9c6-d2be8cf130a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:13cf2419-2c31-5020-bd99-bbcda8589f6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d89930c4-16ca-5f58-93c5-fba23bbbae83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4dbe927a-6123-5814-a597-fcc72aeaaf49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:937d89e0-d85a-528c-81e6-14f617d68fe6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:90618b08-d702-5d5e-a8aa-66f2c7d48380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75a7441e-3b57-5fca-af84-617bb0e02730",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54536c67-28ca-516e-abad-800658eb1c48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4934fd43-f8ea-593d-825a-be95efc01310",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9d2d198-98e9-5658-9921-0e37f1413c81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6601fc23-2fe1-5dc6-9bf8-261ca281502b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a05eafa-4bb0-5bef-8f27-57f90503f24e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ae6a99c-c4c5-519b-8bad-352eb8488c5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53e092c8-2414-5ba3-a026-a561635c9e50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2bb0f54-cfd8-5ce4-ab69-0ad67a3040f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59bab00d-9c29-5095-b38e-7ac00d7f13fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:63059394-48be-5979-a06e-8615361c081b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e2f943f-b949-5e7a-a33d-144d5eb6f6a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a916b1ed-3d8e-5a17-aea2-92b3d9746c6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a59e5b2-3479-586d-aefd-f8d65520c945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3d7451c-56dc-5afd-8c44-e4f0c17dee39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:47b713da-6cbb-5147-a44b-b69b281eb95e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:665c3f9c-f816-5c8f-a184-8be93018c4ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15331d47-e905-5ef5-a6c5-4ff8c5bcdbee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e96a073-ced2-5341-8892-cbd44a0b803b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:afaa1883-a6a2-5f18-914c-41f72b5d997a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:96c33936-302e-5a51-b791-afd428a58192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0acee7f5-4757-58e6-907e-e0382cbb6ee3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fe83aed-e6b5-5fc5-b2c9-a9efd69f9001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71d99c14-fcc3-5e83-ba9f-8a9c11cd0581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d9d7bfe-2494-5abf-8cf0-f22cae1852c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:012a4ca5-8082-58ab-8d5f-aa622468caa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2cf9dc68-d0a7-59d7-9214-cf4bff45998d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4dd5163-930b-5b3d-a6e8-edef411cb234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:98434784-6b23-5e07-8f34-f17c699ac7f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:29e4a21d-4917-5551-b866-1d9386614855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b6f734e-0636-549f-8ce9-e684ea28320d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3657527d-6784-5acd-977e-d834c5460521",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74802d9b-6134-5d25-8a09-1ccd2a6eee35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:04efd58d-9e6a-5677-a1f0-2fdcdd85a71d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a3e8baab-e2a5-5929-95e3-f6c9fc00ef6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9eb1d7b6-2535-5f39-9911-0db0b4adac4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e1c3f689-b4d8-5d46-99f7-df13479a3eb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57f95d99-5605-54e6-830c-d95131f6075d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8728f220-8e34-5aee-9757-9daf4109f23f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:417a513e-f063-5632-bcac-10b447e7d3b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b5afaf2-f40d-5461-aab3-35e7e12725d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01785ddb-7930-5e45-b92a-138e5e2671fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb848fab-487e-5937-9a2a-4d62b91ac157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9dda352a-8628-5694-82b5-662fd66d0888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.2.11.RELEASE-tuxcare.1"
    }
  ]
}