{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a061ab9c-273e-5635-8655-8a702e1b792a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jdbc",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12",
      "version": "5.3.37-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5afb9fec-75ca-5cf2-aaa5-9c0461dabbad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9e99e023-20f6-59e5-9617-0f791061d5fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e3932b5a-d206-5795-9d15-04df06cbde16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:68f89f45-c707-593e-a01b-78f9be0b8cea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8e2c13e1-3a0c-5631-9395-391bc2081824",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:aacd9dd6-bd3f-55a7-bec0-42dd90e681f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d8eb855f-66d8-5cda-b6c7-b12193a702fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d9d1bad2-012a-5d19-871b-0e38887d3efa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5d4a9512-52f3-58cf-9045-2951303d35fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f61bad9e-3ab5-5a06-9d91-9cc0830b6703",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b632771e-7dfc-5788-a7ae-37a8d1c10c13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:58259e56-4c4f-55a1-893a-5a55d75cd1ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:eef96593-d87d-5e5a-9b31-53dbca0caae1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:36359bfa-bc3b-54a7-b8e0-67b65ef8cdb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9e12114e-7b5b-5d42-829c-2df9e497d7c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ca49e5eb-3dd8-503c-8728-5605686a5922",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bd207854-a763-5917-98eb-f7da7684f01f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:eedb6970-405f-5e47-b122-10fee9f7bec1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1d223909-c251-53c2-a392-f998706bad00",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4eebdc11-5ec0-5d93-b08e-c9e15773874a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6a726332-843d-5e27-b814-9d3abf8c7e0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:93e469a2-0769-52fc-a39d-9b59ba17ab45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:eb55d362-c5db-59d2-93ef-b8bb54d09c3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ea19a09b-2045-50aa-b5dd-3e9696e12445",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f2b9a1ed-eb69-58e7-91b2-6379db9d3494",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9a45c970-27ff-51cd-b172-263bd67a46a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:356f8d1f-edbd-5e96-9d0f-520e72657063",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6fe5d1e2-485e-5d59-a632-3a75e2d662cc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5c24219e-feff-5dad-b4e9-e0c18af294e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7f589967-dd06-5d08-83e0-1ceeb12696ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4ce0e763-ca11-504f-abb2-f054f4e4b2c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f2ca66ad-bc59-5b44-8b99-9d2fcbfe20a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:72b05c59-b300-5582-965e-175f0734345b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4dc9f1d8-7c5e-5b73-be08-8fb8cb81747a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:241b1b94-c535-524c-a42d-8332521f2c50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a209122b-5da8-5251-957d-b213b658c819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9b09d9a3-d2ba-52a6-89d4-adb61f76943c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6e481e86-86c4-58de-ae65-26a66fd33174",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:76da0724-fbfa-584e-be8c-9900c67a17be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7d592613-487a-5fac-ba70-9585e5578146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fb3640f0-d33d-514b-a929-2c9aa20ced7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2e2fe3c5-fb57-58b9-a5e1-4ed1745a8c58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6e6c6bb4-5ade-5f04-a7b4-b8976caf5a69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:accc1898-d493-56e9-9699-5df5fb80d2ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:992ac9be-7010-5c34-b4ad-b3434d38b625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:46ab46f5-c359-5cab-b3ef-d3e2f0f644d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e63a9ead-a37a-5d83-805f-f48635238d88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jdbc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.37-tuxcare.12"
    }
  ]
}