{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb5e8c2f-1643-56d4-a9e3-354bf78a9ddf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "4.2.9.RELEASE-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:269fb1e7-74ac-5c49-8cc6-ce752b7ef463",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81255050-55c8-521d-9f14-15aff89f95f6",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb1690f-ad51-50a9-9f7c-c549fc4fdf0c",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28a6da9e-4529-5561-b594-9c85afe94001",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708a5397-0277-5e5c-ac7c-e390c3826b5a",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a965d7-3e7e-5664-8e63-17921228dd07",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6510538-cbe9-5f02-919d-19ad6bb5841e",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9e4c3e9-c783-58f7-ae9f-40c76f24c5ab",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78aacedd-3c6b-596b-a642-36e7ce5087e8",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec4fd488-f4a8-5341-bd58-45fe11e6ab9d",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b54f5ab-ce45-5f41-8528-215c81120b88",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e8cf04-a32f-52ab-87cc-6f5a2a833d70",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4288ef8d-f87e-5767-8916-a8058d5de681",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cbd3824-b1de-5acc-97ff-318b7558a4ba",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:456a0e36-a346-530c-9ac5-f8d8f12ee9fe",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe97b4c-2936-54ae-b998-51f2ca5cd5e4",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3d6ab40-7205-5328-908a-1c8a4b38eb32",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:036c7071-ec59-5614-bb01-80becdd136bc",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc80fe2f-9b06-52a1-90bf-a49b68880338",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e7a6ce-4c62-5087-b4fb-e4383e71449f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc142f3a-9c9e-5e12-a652-07ce8878f9df",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9048b3f-5b5a-5d53-9d35-cfbe26c4f549",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdc785c3-96ad-5441-aa5e-0346dea94a97",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:776719fe-34af-598f-a5cf-58024c2cb863",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab9208a0-1a03-534b-a5af-15b53d280313",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1d5a941-21b0-5c39-bced-d9edc730a58f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:036e4395-7329-536c-85a4-c7ba799d1acc",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0e304eb-8af6-5cf4-849b-aa26c4f59e4f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6f8d267-65f0-5226-aa3d-233b5c7a2968",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2564e407-c51b-5dd5-8292-37f4940559e5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dff8c93b-75a4-5a39-a662-ffb5440b8bbb",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a86c4fb-fece-5622-8d5b-a63109f35f78",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18980859-0c48-5bca-b132-9a7a1f3da701",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1e8cdc-5944-52a6-bb3d-88d60f52e6c0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6656aed6-2c1b-5f97-a3d6-5fe4b4729bf7",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715336d6-8626-5ef8-88d8-6f834f3fb907",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b5f3aab-b1ba-50bb-b790-d99aef3856d9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32dbfddb-bdfa-50af-8166-0fc4930c49e3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c0671b-7879-5c00-9f94-aafb91fe62a7",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bc7c5bf-3872-5307-abd5-75471664d687",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:025a635e-3e40-5645-8719-189ef89731bc",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c852a6f6-9f4d-5994-945e-39ad381d4778",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07acfe36-0b45-5c7d-b7f8-07cd38ff00cd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f60571d-ad17-5b8b-b714-0a720eb4a097",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b10ffa3c-17e1-5fc3-b2dc-e5af9549b051",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e9ea27a-8d3b-567d-8ee4-3af8f825b7ab",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.6"
    }
  ]
}