{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1b01e84f-4934-5e6f-bd28-284587d7e0de",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2",
      "version": "5.2.11.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:73d3dae3-0fe3-58e9-aa93-d3e8afb5f9fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:400559d0-0821-5496-974f-477983ca48f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9654fcbe-013d-5d37-b807-f95618249f3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a89ddebb-f878-5017-b60a-586202f651df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b8aaff7c-4893-577d-9e94-3307c703f1d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84994ba7-0a02-5752-953a-f103c44ed175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:926b667d-24a3-5436-89d7-42fec516b756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:71b27b29-3bd2-59c9-8f41-ac37b9973ca3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc75c877-63ac-599d-ac1a-49bc43668a95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7863918b-3056-56a0-86ce-cfd3fc86464e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:001713f0-728a-55f8-ac90-f5fb616ca7bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bbe5d5e4-42c7-5caa-bc2f-e75132f64ae6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:503a6dc1-7793-53f3-8ade-39c88fb12131",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c41ff1c-49d8-5b5d-8870-1856debe13fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:95366b5f-0941-53bb-b6ea-eccb8eca8f48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:327257a7-c44b-5fc7-b12b-92891850baae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:427f2403-b68c-5ce9-9a35-cbdab3409a28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca18b485-43da-5f25-8cd7-1436a2c2c905",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6a34c9e0-10eb-5dbe-a59f-8199ff50198c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c232da0-94f8-57a8-aed4-b1106eeeeb91",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3cc8f0e7-fa98-5cf7-a5e4-eb0ee0496b85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a8927bac-c765-5e5c-bb87-1bb50df53341",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:78e75f5b-f3d3-5cd1-85ea-12fb147cab38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a9c5757c-8013-5a70-baa4-2561dc753557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:25c23330-986d-5ca1-93de-b10e459843bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6d599430-795f-59c4-8d8e-926de9351224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aff2de7e-d758-5b34-9cc6-852f0154c758",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bdbf729d-31f5-5286-be26-272e841dbed9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f635efb1-05fa-5603-a9cf-25354de597e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:340bb28b-02b4-5671-84f3-051073a343e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b61a9223-34b2-5bf5-aaec-7be73cb38638",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b92cd116-35ab-55f4-8a4a-5743fc39a6b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7d54e20-3588-5cfa-ac26-ae5497147390",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:89661d47-7c3c-5990-843d-9d1d6a0a0c2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fc233126-40a1-5807-b87c-7f16cc71b391",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3df8be67-9bc5-56ae-8a19-3a86a2b4fec4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a07ff2be-b593-5e56-8513-8e3eadee2ef5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:753f1378-88cd-5168-b7f7-547fbe6c1cc6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:221348c3-ff08-5a4a-914a-84b24450e239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:36ff1e71-fd2d-59f1-a84b-2c656c283327",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc63b7ad-96c4-5de4-bbbd-4ab29858483f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e54166a4-d873-535d-a203-2a18f7ca3e54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8645e3a3-fcc3-5b8e-b0ee-fcfcce38095a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:24eb52fd-e550-5075-8a83-cfb952242ca9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3b30b91e-7265-5bf7-8cc9-bd596ff4bab0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ab888edc-eea2-59e2-beeb-2c9727229b39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2faf44e5-d856-5eac-813a-6a0ae50a6034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ad39eb12-003a-5ab2-b0aa-51bb188b806d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fc8c88d1-baa0-512f-8afe-79c30e251784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e69966b-0202-591c-a3f5-ea99047a9cbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9beb8d04-a606-53a5-a055-cc01a6102292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b1bfb975-bac8-5fd9-97ea-c4a5dffe818f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45608fe6-36d5-5b10-96f9-38582fd6f7c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:37a77059-0508-5f87-b965-3cfe877c8b27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f3a4820-51ec-5352-bf4d-631be222c05b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:800639b4-1749-5e72-b211-9f789504b275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:26637c2b-2029-5ebd-beea-d572a28f8588",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e4dde3bc-ceeb-52e8-925a-959e41c8b76d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.2.11.RELEASE-tuxcare.2"
    }
  ]
}