{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af65e1de-bb6b-5f13-9e9c-03f3c27a051e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f7037d83-6f47-565e-80a3-47acbeaf0744",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3b8ceb40-e64e-5af3-826d-e11d526a1a21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4da05c80-ba87-5b4c-9fb4-e23078d64645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e7135cb4-6dfa-5e55-8a89-08d5cdf5c3b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e21994cd-1e70-5f3f-a07e-3aca9bbf7ba1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a95dd4fe-e237-5277-92a4-d531f638f657",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:805a5ce8-15d8-5a06-aa6a-d2b779dd1c48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60b74022-ee35-5e07-951c-b4368b07ad0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c5bd865b-d1ba-5d10-8d41-2f1d6d226849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ae2af2d1-f6cc-5432-acae-ec33dbf7a1bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6bdf59ab-8937-5767-a23e-90016fc5df8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a4a88279-37e0-5409-a320-f3ffc03eb84e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1454900b-c80a-5051-b89b-3a874231d370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:572d8f36-9724-5e71-aa67-6390d523ac11",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9b1a7c39-c93c-53df-ab62-c791598d6eb6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f75d0e3a-6330-53ed-bd60-eb868473cd3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e291a27f-3f21-543c-a5fd-3d943f09fdcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:995545b6-bdb3-5685-b251-f52539315a4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a68644f6-daa0-5450-a0fc-f030536fc6b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c97000c1-b5ca-5c58-9df6-c962e703a420",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:855cf6b7-499b-5fc2-87c4-f67b1c0a21e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af0f3a28-8cf2-591a-b0b5-6d2d09816fb6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3df4049c-141b-5b6a-9424-c9d873926314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8810eccf-cf82-53e1-b042-d7123c245f29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e0ecba45-e4f5-54e1-99a5-02ead33188ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ea6edb2b-c6bc-5e37-b9d5-e736b5ff71dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:55fc7e6c-06e1-5fda-bab7-9dfcac800cc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2a796a42-4997-593a-9bf2-69472a26d46a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67608d44-32c9-5898-88db-733f35a58c39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:efddd753-040d-5f36-b8c0-8aed7d2fb6f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:233ebafa-23ba-591d-a2e2-a5f26934fb8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca8069f9-3610-5222-8ea4-e36cbd6880f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c898a432-c73d-5498-9e99-05140916868f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:805a00e5-8cd7-5bb4-bedc-f7e81f26b413",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8dd1ace3-1682-57c7-8330-4cf339588985",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5825588d-3880-5438-bdaf-4b5691a16060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:090d5003-aab1-5464-8872-d794e2e999aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a56393a7-0b00-54f2-b11b-6a6d403fa8be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:96afac07-c858-5f6f-9d6a-bb5594c0eedd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:88e8bf50-f893-55e8-b06b-3a748a8c42ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3868f1a7-fe9b-5689-a45c-a7109402e69a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:50f67fa9-411a-5851-a959-8f2557ff3fc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9507b86f-5112-57ad-8537-7bbacdc5cb65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4de3b9c6-4efb-5c3a-8816-c2ad1e195b68",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff969151-f9a3-5c3a-88da-1c67931fb096",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eb9f172d-c3a8-56c8-86df-8c85d660ae63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f687852-f135-5213-8c5a-d55946d63146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60a51cec-e38d-592d-a15d-8c41ac2c2521",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c1dc69b6-3e81-5b86-8674-643482830c10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0adb68d3-ab1d-546a-8f56-95035e704343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7d40765d-80c5-52c2-9709-57d21cfc859e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:56db1e1a-7d0e-5af0-a523-80574e351d4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:163c4b9b-9b88-5ae1-8d91-c239147f2656",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e4dfd5f-b95d-5274-a082-8f7b4e5dccef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:81ced97e-7390-5f4d-bafc-24b0b3c52029",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:26742262-df35-5a30-ab5f-cba4302863df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ceb397e8-8204-5d2e-b1af-47ea8a17caad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67cf0238-a4f7-5769-bb8f-b55df2f508fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:34b165ba-1b0b-5a82-a08c-5ed615e1f430",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7b3f4d13-a6f9-53d4-8f3a-abecaca66396",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:89eb6b2b-da69-58ba-a42a-70921f0ac9a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.6-tuxcare.2"
    }
  ]
}