{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7f066b27-b514-5493-bdc4-c8357f2ab518",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2",
      "version": "5.2.11.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d4ad7ed-8505-5694-b69a-1668ff911727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:27ab0f37-8ff6-57a2-88c6-cc1477d88c9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74675e18-81b1-5f2e-ab29-b3871b486515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4afd5c9b-a1a4-5fdb-8844-809d43433847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e41d1ffd-3ea9-57a6-afbf-a13542093f02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:57525ba9-c78d-52cd-a9f8-3d2bb0152d83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9eb6e455-28b3-5487-a5ce-07d98752061d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2dc41c20-7539-58bd-b030-9b73af6f0724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5aa1c031-8431-5507-a656-8a2b1fc21fbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:be2e1389-c32e-54d4-998b-c2a3e0361490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3b9da55e-cc41-5bc2-9bcc-bab6e508709d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fcb15ba5-ec14-5204-a435-4d23b3cc573e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ccc1afc8-8d8d-5302-8194-f5e88e8acd05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:69af8b90-6677-5c0c-8592-6809777c5316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:10d37eea-dfc8-5e1f-9442-2e692f8a6363",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7e564601-927a-5eaa-a9a8-5e7ec05fa7a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:86cb8577-9282-50c6-b4c1-22fd02790c64",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:37243550-2a33-51be-a7ab-bda5376f5c0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17b8fe95-6a26-5f51-b0e6-78a152350ced",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7b6cd6ff-6343-5122-a0a4-185dc50ef6e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f5c66993-0256-5643-8923-5a6ac12b9195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1faa3bac-763f-5c32-a75a-5138f975c349",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97d9bfe2-fd6a-54ae-b49e-84f13fc43d6c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c4ab8b25-3530-53c9-9a95-7aab5c4c9f23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b1e85855-dd82-583e-8c87-2ae527e80d67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:710a717f-31de-5884-9d8f-e59b1b92fd0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b16a3c9c-fd3a-5269-8acc-7dc38c99055c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b51bce85-52cc-5b84-aea9-a609b16eacd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5eedfc02-ac4f-5241-8e5e-6152bfadca69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ac1c1105-2cb6-5a44-a7bc-db4822576918",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:63c5d77f-61e9-5352-9e55-18d9d8f565f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:40005a03-e518-53d0-9402-d99c34422544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:638d518d-a40b-5695-9343-e80f0c98e992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:399cc8c9-d004-5039-bb39-913b4ad94da4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:86c6384b-7abc-5c9c-b0a3-c9504dd892a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1955aa7b-d322-5e50-bfa4-d81bf6791f82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:162b978e-0a34-5d27-8112-b22a9e5777c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6405154b-973b-5311-8b21-b299bd5e64fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5527e2f4-d06f-53d8-8642-e50070bdd760",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d61c2c55-5490-5baa-a196-cad1875b825f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d79c91d-9476-5e92-b15a-433291e628b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f9a45172-90d9-58b9-9522-aa34b194057d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4cbdf0a1-92d9-5604-bcf4-ae90a88a0a80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8763e839-4ca2-55e5-9659-9d7a3939a8ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:688e2cd5-54ad-5fa7-a5be-4dda7f11df47",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97d031ed-8c15-58c7-a84f-36bfb079e3e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:372e08b3-e19f-53e5-80e8-60a88d0852d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:53cbd877-91c6-557a-abb6-194dd869a285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d061929-b701-5a40-9be8-db7afe2c9c4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fda747b9-a4ca-5c53-8fbe-0a583d5ecc96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:24e6232e-63a5-54c3-b422-7deea2b55b38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d87b58d-69d5-5fd5-a249-bc67aa8a1ade",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bc4f9978-0161-5f36-9e91-dd8fb09739b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f70d2c5-5bf6-5a98-88cc-5d25f63137bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:66faf5df-b46e-583d-b103-2c84572433ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5b0b96a6-b751-5ede-acba-b272f9fe655c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:814b8544-0410-5012-9b02-f92cb7a309de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ebc42a8b-0047-509c-8702-2db7dbfc441e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.2.11.RELEASE-tuxcare.2"
    }
  ]
}