{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3fa8fa87-423e-5978-98e1-79046b293526",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "4.2.9.RELEASE-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ef5b98a4-589b-5f41-ae08-14b8ef779358",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52a26e9e-31cb-5907-9702-753103e1f72f",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4fbfb46-6609-56d7-91b7-f92cd07299c3",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7561fa7-12db-5450-ab8f-23881f0bb9e9",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5b571f0-1721-52bf-a224-aed634c31978",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e617446c-b306-5dc1-b1b9-932fd0b26086",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae8baba-24a4-5afd-9218-ec77a2e00e2d",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdfa5252-df99-53b4-94d6-70f1a3a22a06",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8694de0e-acf0-5d7a-a927-ef2688e252c0",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92070089-7c37-5bef-b9ab-55ea0f4e62a3",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1a2289-bd03-534b-8e51-90d622edabb8",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e59a0a05-7632-5e57-8a79-ee853f08dc6b",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:325abeb4-15a6-50dd-af7d-93546fdd4a17",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47934cfd-3ad4-501c-aac8-90cae8542bb2",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00f41687-ce0a-5d4d-b785-9f7eafe986ba",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a55ef005-4fc4-5e9b-b2d5-52efc4cefd48",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfee64fe-6311-59b7-883a-c51d13491555",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eae54a70-6392-5f13-93b3-f66215f110c8",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a54d78a-aa6f-59d9-96b0-a6ab03fbbb14",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81fabb0e-958d-586b-8317-7b103602205c",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee15628d-e12d-5ae0-bdd7-0f1a3523b7d0",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c45dfab-672b-5417-9dda-29614f4f0d5b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b62c8335-3ba2-59d8-af28-eb4c8daf9a7f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:493329a4-a609-5357-a997-41f8161b8341",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd407895-ff9a-5cd9-990f-7b668f9248a3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de5be8b5-605f-5d94-bad3-3e04608b5c6c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb741997-2a4a-5b96-a121-415127cbd308",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2570795d-9b09-50ca-9e53-35f74d627a67",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52d754b9-d703-5b1f-93d4-f690f3cbe23c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccb69280-4577-5d3d-b2f0-0271ab9ad815",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82fe2c9a-bab4-57c0-8c8f-c1e850899d77",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4925722-a792-5d64-8040-f6764fd31656",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dbd5bbf-5412-56a3-8e7b-473879df54d0",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1004a308-1bb7-51df-b3c3-4889a1636d62",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e6e4c8b-f287-5198-a16f-b317952caa2f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d363058-d760-5aca-ba57-a5c0f4418391",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c02b8fff-4d94-52a7-9e31-0b10302ed879",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc9f34fa-933f-542e-810e-3f407ae3403a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d18011b9-373b-57c9-a668-566ab8290093",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80f5c40-a6c7-5258-8a16-472de221a910",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf7163e4-4050-5145-a2d1-64f9c48951c4",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7831cc8-92c7-5581-ab67-55ccca3b26a2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c0f1523-431a-57c4-9439-ef2a08c04f1e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a987cf3-0c18-54a3-90ed-04767dcd5568",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0310ec22-262b-5825-b734-90e7b0bb226f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de96a089-d7bd-5a55-8a8f-2f82575cc5af",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.6"
    }
  ]
}