{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:05997b35-c842-5908-a42c-0de3da0e1e4e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring",
      "purl": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11",
      "version": "5.3.30-tuxcare.11",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:0f055aba-938f-5837-a400-0195884a2dd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.11 of org.springframework:spring and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d4bd9221-829a-5c17-a0c4-fcffd7ad409c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a0649125-8a09-5895-a320-748a3f7214cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ce898029-f212-5c26-ba27-d44013c30de4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:6aafc828-748e-5bee-a6f0-dab15cc297b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:59a8dd5e-d0ac-56ce-abe7-4c868dea10fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:dc8dcf71-c74c-5ea4-9e22-105e59ef042d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c533c2f6-c18b-5845-bd7f-a156db67df2b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:69ea8ce0-7e58-586a-9ca9-cba3168923ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:731f2f49-4dca-5f7e-a107-94d4e4d761ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7356726c-4baa-525d-bac5-fde32df945c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:8ca241a2-5645-5fbf-8009-10d267aafc2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:621ccfcb-5048-53b1-91c5-fca801633666",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:521d48a8-1a0a-5411-b239-a2b6ed5a58d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7d5047fb-7c65-50ff-9a6f-06a117ad45b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:53839b17-f602-53a9-a2e4-f77f9ebcecc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:31b852a1-4e7f-598b-b0ab-d1973d22f81e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:895ec0c0-1e3c-5ff0-9d34-0577fd4d29df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ea7588e1-bccf-5524-a4fe-b88a9eb5d037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:b290b492-40c6-56fc-9959-e39a3aa6b21c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:9d2891d1-2faf-5500-8978-58bb40c4032d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e6a0e034-917e-5838-8410-2dad1cf59424",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.11 of org.springframework:spring. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:327ad3e8-32d5-52ea-90f5-fc9acf97a271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:0b117906-d7a2-5f3f-8933-da5983f2ca14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a0fec05d-02c0-5753-8831-573fe5c5cf7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:61b9dc09-72d4-5dd9-9ed7-7f09b7377e45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:1efe837f-ee40-547b-bca9-a9e0942e6556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:311c9c29-7d6b-5ba9-91da-987813eea38b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d93541fb-89cd-54ff-927f-f726509a04c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:cea96868-a616-533b-a7de-cb65afd3437f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:7e3ac33f-5d42-5671-90a8-652cb349e69c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:82bfdd79-c3a8-53f1-8c20-d5c83ad0600b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:6eff86f8-e124-5d00-94d9-2c9d4735a44c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c10435e4-45d7-5364-ad39-14e574b0c0be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:2350b03a-7b23-5a8e-a0cb-24c674c73307",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:1d44a4b1-6410-5217-9641-6f4eb44fd239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:84fa92ae-a395-5143-9a36-ce930363c5f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:3ce5cb55-00fa-503e-9d67-c2f21f199d5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:9ee2dd5b-857c-57e7-ab5a-472388e74409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:1101d727-f322-5517-8592-175deb0eba3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:2863858e-8b48-5c7b-bb78-4dd9a291c906",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e9be99cd-18f8-5a70-bce7-7cecc16d7758",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:88884e85-e300-55f6-a5f6-4ce3dbcc2c12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d9361812-7af5-5c93-853f-c79c231145ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:35afb4bf-eada-5ea1-a12a-82a8edc20b3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:bfdef6cc-02b7-5bef-ad02-5789cb4214db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:63da7cae-962c-5406-8e80-89dd9292a8d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:3be903a7-5b71-5e42-9535-11d443049f8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f95c604b-c296-5892-89b2-180d9cfede07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:9c39fd05-6ba5-5ffb-92e6-b14f6a5db86e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.30-tuxcare.11 of org.springframework:spring."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.3.30-tuxcare.11"
    }
  ]
}