{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d75e820b-e0f5-5c97-90a9-bd33a30ffa16",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jms",
      "purl": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12",
      "version": "5.3.37-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2235d936-44f8-590e-93e3-5bcf14ce50df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jms and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e1ccdee8-278d-55f3-a9d0-a36b89a42807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c9a8f3e6-db62-597f-9a12-a8e00b3f0d62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:397a662a-04e9-5827-8046-293562a6b993",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:be649d8b-7393-5543-8bc4-aefe8055b796",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:486575f8-b5d6-57c4-9df4-f41bd3639d83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9557bd8d-a890-503f-b024-23dace0f1fe2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b121f763-65f8-5f4f-8f02-c85604e927e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:42009087-dd61-58ea-b1b1-462fd5bb5294",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:451b9781-52fd-5695-b1b7-3316f0c10178",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dab58289-f18b-5f27-aa1c-3341e71d0f02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4230aee5-e346-57a0-8bcd-0147caf595d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6699b815-5d0f-525c-be4f-10b779e93081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ad5304f4-d7b7-5bdf-9c75-9048341de510",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8806f93a-f5dc-563b-9609-cb1c2c61bea2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b53e3230-3172-568c-bd97-de4b87292d09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dbb5d4ff-6d2e-5fb6-9c03-c4f90799832e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ad1ea3e1-ed25-5048-94b4-9810cb219ff6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cb000c89-6209-5937-8ff8-1ce85c2330ae",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jms. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:91a887c2-94a9-57f9-b041-1fc2c779f873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9d9617f0-8564-57f4-8061-02515d8af056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cc095751-1d52-5c93-8d54-912f0d0ed68e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2f3d1ff9-c40e-52ae-b252-9a8814593b82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6d4f4aae-4f4f-5273-af8e-9b6b25a2b07f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9a233dcf-049e-5ad5-87df-905383f5575f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:822b31e8-742b-5fb2-929d-2d00ac57c7af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7d6f3b7d-aec8-5e98-bb88-2156da48b1bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d081da4b-6a77-5b9d-b383-3ac65e5c9591",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jms. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:883f1c56-23a4-5e72-9b13-ed84e20605a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0bc47bc4-8d38-5b0c-b98e-b1f9f0c4349d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:880d149a-3f84-5ae4-81fb-ea01b06e0d53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6fff893b-9558-5464-b10e-dd7b8304d792",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:59a0d87e-5ffd-5bf4-9d4a-1a8326c42fdf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jms. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:62041823-4422-54cc-905f-9dccd602bf62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:01ebac08-3bf1-5c49-8c18-2c31bc350309",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a537e686-ae61-5ab8-b9c5-6d4010864217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:50a75074-fc7b-57bc-bbcf-e99789c296cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4eba8cfb-dc69-5316-b8aa-1b5993bbf342",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f51f9754-8aed-5119-8e8f-d9728e5c51f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1f75513b-7061-5f64-b7af-e66969b0ecb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ee8c2851-b61a-5124-8e6e-95d581d32ebc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:93ff2310-33a2-59e5-9a01-cbc0a40d3da7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fe13b6e1-1ed7-5483-a64e-d5aef3d0758c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b88c48aa-3df0-5814-a26a-e7ae5eef0a9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f606de79-db60-51e8-b676-fb93a5ca9d84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:19da3d77-8c7e-5a1b-87b6-fb3eaea4073e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:86416790-2522-54d0-b3cd-eb6810a1d4ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@5.3.37-tuxcare.12"
    }
  ]
}