{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6fa5b96d-1206-5306-a8ae-224027f73bd0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-aop",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fc378cb5-a2f1-55fa-b47c-8941da5fe39e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5034b8db-172b-5f46-acef-e70a3d1108b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:09521a42-0339-5045-a5b0-bdf629cb696f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5527474-ffcf-5630-b76f-c247a1928616",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:26ef958a-68c9-5b7d-b8a4-ee58f1d02be5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:33fc524f-7de2-541c-8a71-9a18ba99e544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d4763507-6b2a-55e3-8540-c50f5f3a6b3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2d2eea2-6ba7-5521-acca-1325ac0047b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:396cb7ec-416e-509b-8c84-e82bdd699ef8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b3f336ca-705e-5e79-ba5d-454c32783f11",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:46fd6ca2-7888-5484-b4a1-cebc83f35561",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a6913637-7825-5f1e-bfc3-38da68ae304e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58e4bdfb-9fde-5691-b193-8000ae6e8f2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7b7d3cb1-6702-5ead-b866-9f42299ca042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a59a3ee8-8fd5-5f86-85cf-2097d8a1d34f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:61316220-1a94-5506-b11b-1626e3248321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:425e6afb-9be8-59c5-a4cb-5e589180cf1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de69b130-34a2-52af-af08-e8da622bbf30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:63961955-4e2c-5cce-8ab6-0ddc2a61cf5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:645c7354-6bd4-52c5-bcc8-e6cbd8a24f2d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-aop. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4112a8d7-6571-547c-b99e-2c29b94c0784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2806c0c5-85e6-5cb1-a0c8-153b0791706c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e960f285-18fc-5e11-9d35-06a6173bafdb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67d78992-9aaa-5809-ae71-66ef3560dc3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d4f54c5-f96e-5cfa-8048-185c82d1581b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c599ee51-921f-50f5-816c-1f960b18f192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5a8aa249-9330-50e3-99b3-ce5ceae34a21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e59cbba2-c060-5c21-a9e1-9230d6206eae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4c547ebe-4c3b-5160-8f0d-7bc1e9235fa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:548a84d8-d59d-514e-94a0-d65e43f6d73b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b545fb97-bcea-546e-9806-51cc5ad13cb6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:092b2e19-a017-5e1a-a1e6-835722edf0d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bcc491b0-9c34-5681-9c9f-5ebc66549b4a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:06447b76-763a-5445-a814-41f022f3f3df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f6ee9e3-ff51-5842-8a32-f24e59cbaba8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eca915f7-e522-5a66-880c-ad2cd6d9f235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c1fe8d45-7429-5310-8d57-e00c29de4d17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:18a01488-5730-5ac3-89af-dfd192e15020",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4b73391c-dfa6-5466-942d-423fe29a7132",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a1b21c90-b7c4-567a-9b70-98de45f92f3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:923d1719-77d2-556e-9763-8e4316a3b5f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d1f429b1-825c-5e68-88b9-033c1150ba1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ad022ef9-168e-5444-8b43-b646ef77744b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e596b802-bef0-5f59-a63a-115f28b0e286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:22054077-5ee0-51a4-b3d5-add1ab6b2c84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:87d2cfdd-ec72-54f3-80c4-04edf28e6240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:124fabbf-1c3e-5ecf-b338-ae4dc2c9877d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5f4ff08b-5379-5a79-923c-b22f54fbc668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a3d5a6db-2c52-5143-a272-4618cf8fee16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43800035-9ce3-5c29-a2f5-68aaabf249aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e081fd68-fd91-56a5-9169-4670c1985353",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:381ee356-a871-5d99-a263-68e50705c32e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:52bad349-9d76-5e8e-9a37-727ffdaa9ad2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84b1475c-76f9-50ce-ae87-7312a9e1e388",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:596a0942-eeca-5938-9987-411d462c9c44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dd97c507-1938-58a2-855b-442ba4a44144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e9ff87d7-9fc1-597b-8bdf-85377d9614d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3702dfdd-3148-5555-ad4e-791d5aef5ead",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:46e3b2da-1651-5d9a-aba2-bc3d09212c69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3f1d64c1-6b13-5c94-b0e1-989e31efe01b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:758fcc19-2966-5edd-a227-2df48b685899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-aop."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.6-tuxcare.2"
    }
  ]
}