{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:94954cf3-5a17-5077-90d4-2127232f621f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1",
      "version": "5.2.9.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b13799d-9c98-5494-9994-0663e5865b08",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1f276252-6745-5316-88eb-316490ed554d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:43013af2-f8fa-5356-b9ef-a46d3d878e12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9cf4f3fc-6226-5c01-94bd-470aab0cb0c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ec878e7-a811-55ba-9232-557620ff2b00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:61288ae4-2ed5-5d69-a540-5fcc6f93d34f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb98c0d4-6926-5899-8d82-6d2c121370b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4cca64dd-9b54-50ea-80d3-ed03163d6798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39824cd6-d6e0-5e21-ba89-bc48909e36c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:92c71ff4-beb4-5c69-9f8c-aafd9b0be84b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ba66c32-d11f-5735-b3c7-46cb5a295d5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d99f4238-8f10-5812-b5c4-a98363c0027c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:07a128f0-a09f-5605-b7ad-a9d3ee3dc65f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe8040cf-0212-5413-bf2a-c9d43236570a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad8d6464-ed19-5cba-b936-e9b22465e456",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e141e3ae-2a37-56f8-a5e6-1d5d2e07a788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86623b6b-fe48-508b-a94a-8b26f0dbc0a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fcaefed2-68c1-573a-a3a0-540914058394",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd2f29e7-cab3-54ae-90af-141a6668626b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 5.2.9.RELEASE is not affected by CVE-2024-38820 because it lacks the vulnerable code pattern. CVE-2024-38820 fixes a locale-dependent case conversion bug in DataBinder's disallowedFields validation that was introduced by CVE-2022-22968. Version 5.2.9.RELEASE never received the CVE-2022-22968 fix, so it still uses case-SENSITIVE field matching (no toLowerCase calls) in DataBinde...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a54c892-6f7a-5c26-b279-9c5f9f9c516f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db8eb41f-b666-51af-b4b0-28d153a4f3ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d895af0a-1ab6-56d2-ad2a-a2c247c795bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b01fecdb-bb16-5a29-81a4-b871dc52fcbe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f134882a-f10a-57e7-8cca-0e1d729b9bc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b9226409-a9b6-50f9-b175-68690bca03d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:23ff04e9-0ed2-583e-9876-fe0f31b0efe9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15ff912f-7ade-5fde-8144-db4060f16c8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2623a04c-729f-5d9a-8fae-2eb154697b07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ecd6af7c-91ff-50bd-b5d3-a04ee21bcbc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:384eff14-d9a6-5bfd-86ea-ccecfb15e9b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9b9428a-3870-5a3a-a666-f029c0397571",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2da5fce4-d6ba-589c-9549-94ce73a3818b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cde74d0c-f2ec-53db-8643-28efc9e3a6bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:185a7c66-3b4c-5ba6-83e5-c0950dce5c9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e7b9426-454f-5354-a8db-3c014920d385",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a969916-f141-5628-b46a-98ac0273c9e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:375c613f-a7cc-5b7f-8d65-c6d94100514c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6bce1e8c-1868-51de-872b-c3cb176fc17f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc847358-8c63-50cc-bfc9-c5bc481501ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:95ec39e1-a99b-50c1-bf1e-def94daabd51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:518dea9e-b87e-5372-b7ee-9929427011e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7f65be45-332c-5525-9865-5c080a057864",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99daf29e-8cc5-54c4-8419-5af9ca9a6f39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5f49f46f-a28f-535d-bfa8-4e02c8910015",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50c32275-2d36-5306-bc97-a7471c8d4b7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6a9a672-ed25-546c-8750-1f5b07521099",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2dfd90c4-2ba9-53da-acf3-1f6627188b8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c119b44-95fc-50db-b316-3d2530ebb8bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8435e0ab-a667-5c65-809b-47e2d2f8c8c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37a45e40-0fc3-5760-bab4-919b6793feeb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0373776-50a4-5c5d-a3e6-d064a02feb7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b76f488c-8345-5a63-aa2b-920ae00f75c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:866dc1da-6ce4-5ef4-85d3-4b98fd8ea550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85ccfa0b-2f64-501b-9abf-bd41583e02ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:362cb7f1-8709-59e7-a9f7-f1e580d037aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39f4091a-6f18-5f8b-ad47-59558ed4b932",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e123047-e76e-5c78-b4f5-b271111cdc78",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12cfecb7-7cea-5d54-afe0-c180bb12fce1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.2.9.RELEASE-tuxcare.1"
    }
  ]
}