{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:27ef3588-e846-5dee-a561-6d4ba0a0ec3c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-test",
      "version": "4.2.9.RELEASE-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:97bed9c6-7599-5133-9e13-73beffaa0c8b",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d914009-8e18-5752-ae3a-d1febd4c7cb4",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41dacd46-e42b-5ede-a755-3ea3fa43987f",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee2e4190-fa3b-56c2-9256-8eb07db310b4",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55390520-8411-52c5-a060-58a340f329ac",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b440a45-9bf8-5317-b668-32c2e32f4a35",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49d1ce32-8f63-5613-92e1-5246a538f272",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f56077f6-04c4-592f-998c-022f4cd318c1",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8619bd26-4ea4-59b4-a3c2-939ae82a6615",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1a05ad5-9510-5021-beef-bb0a541a3242",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8824deca-49af-5ddf-9e6d-0463f0714052",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8dec18d-8dda-522a-aece-232e7eddcec6",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79bba5ec-bfae-5501-b2a0-16053dba7e0e",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602c7b27-eb58-5907-9142-515ea88e7a44",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a79a0b-1127-58a0-b615-bdb629ad6ce2",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:565082f0-76a4-5f2e-9f4a-4b776d032f69",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e849ea86-5fa1-5a16-a736-df81d389b254",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00fae22-6d24-5dab-8624-748a294eb673",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18ebcb8d-74df-5dca-a5bc-14cf8baed45d",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a3eeb30-9692-569c-868d-b066a682102d",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c39b5532-0890-5315-9014-c1f2b24530e9",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38d68c97-aa62-5168-b7ff-2d1974c42c90",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df7ebbd8-ef44-52b3-bf6e-65b70e66e2a9",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22c99920-22af-5c31-985b-478fbaadd490",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc274d14-8600-5d71-99da-67ea3a21f59c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e4bd6f5-ac77-5e45-97ef-b31a42bf2d9b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0091acdb-8e19-5f30-a4d0-6b0c7942ffae",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d0c91be-1a1d-5398-89ae-96d813914ed7",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39ed9c4-2e48-5de2-befd-d887644be5f7",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8170124-1a68-5349-b73e-7d0de7bc5482",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95c4347d-f81d-5d08-99d7-e87d0455ae22",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9344327-bd96-5b3b-a85e-0e38740b25a9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54be8878-fa3e-5a7d-90dd-0d7f48187009",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50908ecf-42a7-5692-a838-f7aafc7519de",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27af0047-6197-5008-b1fc-fcaf02123425",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193e8b1f-0d04-535d-998d-6e4a66021276",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02bfe7e-fd1b-58f9-91c6-a30d280cb2d1",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a735ca4-0dc2-5103-911e-5bb02928749a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69d4e811-d8e7-59fc-ae7d-3ce808049011",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6045a0f3-05cd-580a-8783-fbb177566d8a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65beed08-89e1-5814-be0a-15f4da9bf244",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e42306df-0ee8-5613-b83b-e53eba2dc109",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a7b574-a155-588a-b612-22f3c2dc385c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c38bb50e-f230-58cf-a962-bbde66cd1244",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76f31ecd-6c97-5268-8515-834a4e9f2ca4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52353061-5ce8-58d0-9504-70c5434c8785",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-test."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-test@4.2.9.RELEASE-tuxcare.5"
    }
  ]
}