{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:05db049c-0817-5435-b1fe-2a7d2ad6948f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1",
      "version": "5.3.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dd57da9d-f147-5802-b3d0-2c7d1cfdc1a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd6e7ab9-f031-5dd5-bb33-f25e981a735e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0062d929-4fd6-5d4f-8175-6aa1aa288661",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8da90599-2e5b-52e4-a741-5d4193356c35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80a30941-59b3-5952-97e0-29a000a6aceb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48e1760c-af20-5db0-860b-c8240380df09",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc3a2447-38bf-57e3-a942-4636667b4371",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64a88302-337e-55ca-84ec-94332728d8f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5bfe6c0b-ff5b-5d2f-a022-4c229a731d5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3850cc18-e4b0-5ce0-8b3a-5caa01f9c964",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe81985d-1a68-57a6-aca9-23f64c492501",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46811a97-8188-5b10-8f39-558be81d767d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9f3684b-7270-570c-a041-50e5cabc0dd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39143719-a161-511d-ab14-4eb641a3f326",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:efbeac36-a99a-5999-afb9-ec3b0ba9087e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5c565bc8-0f97-5d4a-bf1b-5db352151852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39548b44-0955-59a4-8915-2a2255a6247f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86145c92-8631-50ea-8083-788f3d4ff0b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ea8615b-db11-59dd-95c8-ef8482a0cb00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1127e902-7f23-5fe1-b9ca-c669c30a201b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.3-tuxcare.1 of org.springframework:spring-orm. not_affected \u2014 Version 5.3.3 is not affected by CVE-2024-38820. The vulnerability addresses locale-dependent toLowerCase() in DataBinder's disallowedFields validation (introduced by CVE-2022-22968 fix). Version 5.3.3 predates CVE-2022-22968 and uses case-sensitive field matching without any toLowerCase() operations in DataBinder. The vulnerable code pattern (locale-dependent case conversion in security-critic...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0d99567-9de6-5b82-be76-5375193908b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e42097b-730e-53f5-b364-29767726593a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c67c9695-12ec-51a3-a251-e312c71471e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ffb82d3a-25ac-5239-bd93-26b917ae32cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:047c8e3f-b1ad-5ea3-94f6-74c6f944ab2f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e106a27c-4d3f-59fe-9580-fc640baa94ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66a8fe28-8980-5d38-a86d-a3ceff277714",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f10046f1-ae12-52ff-9b33-ff1519bd7db6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34787b5c-4abe-5e8f-884a-7b760cb75ed1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d5dc26d-b403-5e75-b7e3-2f41e4a597ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fbf82d74-9093-54d2-980b-5f3bec253044",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:131cd2bd-571e-5dc0-a184-7b0ec57a37f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9caea04f-734e-54e3-bf6e-fa0e20640477",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6cbb6edb-8c05-5dcd-ba53-be959090fd1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:77e1bc22-0dfa-53eb-aa11-3a7b85f86a08",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ad80c9c-9da0-5f92-b55e-d685cf1d4a27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b1762b9-711d-554a-b9a3-c6a58b55bebc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e68b465-8d23-517d-8f6b-4e46a25e6917",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:685356ab-ebc3-5bf1-8807-21eb62ce2e7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30dc2cc0-7bff-56dd-8886-c0122cabe4e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ea50fa9-68f4-530f-bea2-1b047ca0ebce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5534ffe8-8211-5c0f-8a00-1d422ea5ab4a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:984fad12-33ec-5074-b2e4-10a0b5340595",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2417dba-b633-53cb-b188-92cb59224702",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7c2ccdd-5224-57e3-b8b2-0a13be82a939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae2e30f4-b66c-501d-99e2-bf009346033a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6efc088e-7fa0-5db6-b94c-db63041fe9e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:abdb19a3-6a77-568a-bd19-dc7e2516b3db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:084fcb52-b27a-5c08-981c-d426334b3590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b30a0f98-d2f1-5619-8fc2-fb78be1f2954",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f12623b0-873e-5b53-83ea-5af3d0f7fdef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f5b5ee0a-1eb3-53cc-a59a-9f54e3d2b935",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:024edc80-6745-5113-8cd5-6e7a3259284f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6748ee2b-2ca7-5d74-8220-bc846559778f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da5d8a98-a7e6-58fc-b949-de401c7b1503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6cfc2e3a-942b-5401-b883-0384adec277a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c6f00eff-3a88-5cd0-b7d8-cb19bd4da74f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f4c48bf-2dd1-5903-92ed-7fd590146ab0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3f9421c4-0870-5226-bd75-19a8120e55a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20613000-ccb9-5c75-bf06-13a5ee4fa350",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:837ab2cb-b3c4-5c1d-badf-ee94f884fb52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.3-tuxcare.1"
    }
  ]
}