{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:014f3a40-1e8b-5d4c-97f8-7a25e07e6a97",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-beans",
      "purl": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1",
      "version": "5.2.8.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc26cc7d-aa6c-58a3-aac3-ff412e7adfcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6bd234cf-aaff-5215-9c1e-7e8498390067",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01bc502f-c7e8-5b5f-a679-08cf5b2fe841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2182c475-d7b3-5962-ab58-9c8e621a1d3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9bad11b5-e4bd-5b03-a42d-34daeaa1a9f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:856aa171-2b7c-5dfd-8826-3e0250ad0206",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b38ea3cb-2e24-51fb-b71b-6916c40de220",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:901844db-33ca-5848-95f1-ebd2529c8ee3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:562e4ca6-fd5b-5ff4-b984-28d69b4aaf7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a6493bf-6293-54cb-9587-551d4e83159f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d358873-d773-5cf0-b0fe-e4d3047fd810",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9df93f28-fdbb-5d75-a00b-973102b3e9e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a19cd4ae-c4f0-57de-ab7e-29567327a048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d01510d-d2f4-56b4-83a5-d5658d682357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:17b3f9fe-9f8b-5565-8de0-a4b59ed67173",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64b914ba-331f-526e-add5-bbaf6c7d2beb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1747bd5a-eb01-55ef-9253-a19cb97ee967",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74102408-7cfe-504e-83b6-3925585f9e53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a202ec7a-5365-53d2-94ba-8ccd130cc553",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:085ef7d1-bf88-5d46-a643-49cfb2285f3a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans. not_affected \u2014 Spring Framework 5.2.8.RELEASE is not affected by CVE-2024-38820. The vulnerability requires locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, a code pattern introduced by the CVE-2022-22968 fix in later versions (5.2.13+, 5.3.x+). Version 5.2.8.RELEASE (July 2020) predates that fix and uses case-sensitive direct matching without any toLowerCase() calls. The vulner...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85f84f8c-7a45-59d7-9742-5ca78a40ef7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6239c43a-69b3-55b9-b327-4cf81183f005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78a62f8b-0130-5ecf-b8d6-6ee0e7f360e1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans. not_affected \u2014 Version 5.2.8.RELEASE is not affected by CVE-2025-41234. The vulnerable code pattern (PRINTABLE BitSet without double-quote encoding) was introduced in version 6.0+ on Feb 1, 2023, approximately 2.5 years after 5.2.8.RELEASE was released (July 21, 2020). In 5.2.8, when using non-ASCII charsets, only the filename* parameter is output, and double-quotes are automatically percent-encoded because t...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6f26b665-28cc-5cde-be3f-593644653c65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e6eb3c6-c2f6-50e2-9993-3d094ecb9fc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9b86e08-7511-557a-b93b-c63d41e5b0f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c992508-a4a1-56da-95e9-0fdc8ed61bed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea2504cd-01fa-575a-b441-1b8b7567c5ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5bf2cf1d-3716-5f4a-8d73-5ef4e4911441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb447835-6afb-5464-8065-1957c589fbcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c73789b6-36be-59fc-acb3-93860d0c22b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:17f87e94-f2b6-5c68-8aea-245fe572fb47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c66b5d6f-13d8-5083-9029-65d8dd39a509",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eee717ef-0807-5094-bddb-f1e62d40fd0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33f8596f-cbb1-502b-aaff-53f61cc82389",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:488dbad8-03c8-5343-ba0b-5c4dfefba6db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:af7ae5d2-022f-5932-a232-3a2922548ece",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ae249f1-c71f-53bb-89b7-e6c48a3664b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a363f55-a5ff-5760-bbda-1403d3cd56c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e3d82ec-a7d6-51d5-a017-8206b87b2178",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1fbe70b-8b0c-5082-9e16-c44296267cf7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ff28976-7eb5-54cb-9b96-6da2e21c0711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e78ea8f6-9fdc-5659-8c82-ee77086dd67b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:812d5e8a-aa22-5269-903e-001da5af235c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5b8a0c3-98dd-5b86-8a15-f659fb833c79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f17a67e-512d-58b0-b979-e123e4bb7b54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16ce52f8-18e1-554f-a690-c5652ef7515f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:054b46eb-5637-5608-b21b-c02370292b20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c25ce54e-8744-5842-a26c-fc2ff700eafe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a51f7e2-1909-5ea2-9ff5-8963eb3abf24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52fdf80d-a5c1-591a-9185-63ba77a3151e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48e057b1-506d-54c9-998e-5df990a3c4da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8dd5e04d-41ec-5a08-a0e6-d94d9d34a7d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bfc23a9f-38b9-5cc5-b197-7721d64b159e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e451b899-056c-53ad-a97d-197a031a787b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c31c8c0c-f754-5a7f-bdc1-969318144dc6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:25ce349a-6a1e-5948-bccd-dd9b3ddc13ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f6650526-15ec-5d16-ae9b-b016bfa692a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b273372-15f0-5cf3-bf7d-3fce6e9f1b09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49872695-ba47-50f7-9e73-01c03a44335a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd7915bd-8def-5ab7-b869-76ca1606ed2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-beans."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.2.8.RELEASE-tuxcare.1"
    }
  ]
}