{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c81833a0-1cba-5324-a1f1-5c9fa41b15bd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-framework-bom",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1",
      "version": "5.2.8.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2385f0f1-da27-5c2f-a5ed-871250fc67c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99fbfbda-05a1-5b7b-a394-8266f15b3963",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e36bde4-8cf1-55c9-a440-11cc6274bf53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ff10136-9368-5703-aacb-889a25b236bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db3dc823-cb68-5bda-9b93-e90da2e1ae2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:346043a3-b9ef-5b5c-b25c-13e6d6741f29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39463e85-3c18-5247-ac22-141fe9af9f44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9e7950f-176f-5b9c-8ddb-0ba6a691fdc2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:718421bb-aa1a-5f29-bb30-24e847c88e31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48987950-8ef4-5c3f-8562-3d89101ccc3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c50be5ed-24b4-5d63-ab6d-c6d1f67179be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7d8f2a6-b686-553c-8693-882e77c725d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f6f508c-d6c2-594e-b835-90a4f5ae16e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6bf42bf9-e4d4-5ae6-b66f-34842bbbd6dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45fec7f3-3e1c-5aa9-a0d2-51f247ab09c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2347853c-8be1-51bb-a9c2-a97145fb0ad7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ec63f4e-2b12-5a9b-a18b-92a17f995abf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c49ff2a3-1103-56e9-90d0-877eff670e0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc53eb58-7eed-5dda-96b0-97f1eb398be4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a48715f6-d3b3-5069-ab19-bcc7c9232c07",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.2.8.RELEASE is not affected by CVE-2024-38820. The vulnerability requires locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, a code pattern introduced by the CVE-2022-22968 fix in later versions (5.2.13+, 5.3.x+). Version 5.2.8.RELEASE (July 2020) predates that fix and uses case-sensitive direct matching without any toLowerCase() calls. The vulner...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89d41800-2fe5-5edf-8098-0460706b1a3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:855f938f-3922-5519-b7d9-4664075105cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5003dcb-8a0a-5dcb-bb4b-d87115f1b977",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom. not_affected \u2014 Version 5.2.8.RELEASE is not affected by CVE-2025-41234. The vulnerable code pattern (PRINTABLE BitSet without double-quote encoding) was introduced in version 6.0+ on Feb 1, 2023, approximately 2.5 years after 5.2.8.RELEASE was released (July 21, 2020). In 5.2.8, when using non-ASCII charsets, only the filename* parameter is output, and double-quotes are automatically percent-encoded because t...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1c4684ed-abbe-5af2-bec9-9593cb10291c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46c2dd70-e006-5e0e-aa81-43684c2e4a53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ba56cc8-7b52-53de-864c-63beed469196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd6f3371-dbf2-5ebe-87c6-5886ca60548a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26a4f077-7197-5f0c-964b-72ca735c0346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ade7654-6324-5c17-ab49-8c53e0955ec8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a8cf4415-724b-5b35-9e1f-7ca4128baa5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:151c5697-c422-50af-8a88-33141e1a19e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:097deb7e-a153-576c-b97f-85ac8243d4ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1be3047b-22d4-5429-993f-e812253dbe5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6f254587-9489-578e-9b87-df6cd0722a35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a7df5817-bacf-5cab-bf57-eae65f9d7e92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56a62d52-d8a8-50e6-8dd0-d122cf53b0e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a9e8ffb-9fc3-5357-841f-b937038a36f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ce6fbb5-cc67-5fad-b8ef-68a6a9e80007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1fa5c2b1-b2a7-51e8-8d25-2e3248a36a36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1123b804-015c-5246-a2e2-128198832c04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f18227b-ee24-57a0-8c69-e24691f8df52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0fa08c32-fe4e-5ccd-b154-24be0369b425",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48337024-5e51-5557-97e0-c64b2f504ba5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0eeabe82-fbe3-5359-a949-0a0987efe510",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18aba4e6-8eb4-525a-9e02-1454f43a0bfb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e29a764a-c2ac-5a91-b223-9a808defb3c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f38d52a-2740-5340-ad13-d943fe76d2a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d509f4b-7028-58d0-b78e-a5f840e4e4a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94e956e4-bf23-5a56-a150-276b0adc1dea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ecf784c-48f9-5bf9-982b-b83b166a2374",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8114e186-501d-526a-91b1-e22676832ded",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7733985b-4040-521d-9c17-5fbd766ad697",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf332e80-bd88-5c05-8272-b4606b0fad6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a78c286-3a1a-5c7f-998b-62b149bbb3d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fe8a855-ee30-5ae1-87cd-4e0236bcafdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d787f734-0eae-54b7-a389-2e3ec83ee17c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1125ff0-6be1-5b77-bbac-ee4732856490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:03d7fba2-3dc8-55bc-be13-c599a1a93b21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9da1c03a-8aaa-5278-9b25-97addf1d627e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:948f40c5-dec9-5dc1-819b-71749ac5a0a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6764e70d-f162-5ada-8013-bffcd57a4eed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-framework-bom."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.2.8.RELEASE-tuxcare.1"
    }
  ]
}