{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:85dd8026-aec3-58ad-9f43-281f3dd00bcb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-tx",
      "purl": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12",
      "version": "5.3.37-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:942d860b-91b1-5c33-b893-0da8ed8c41fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.12 of org.springframework:spring-tx and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7cd251e2-c223-5bc5-8c5e-19eeca2feed1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:604a4c36-09c8-5d9d-831f-6e6bea245c77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8275c486-c9fe-520b-97a2-4381fb059f6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:60fc0b63-69f9-5c50-be82-36868fea1382",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:477c38f5-22e6-53fe-a171-f66671037d0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a22d6ef6-ff0b-5f8a-98ee-a0750c00b560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5b521a1f-444b-5915-9003-ce8454bae065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3d962929-864e-51a3-844c-45111fa783ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c55f541e-d719-524f-9c8c-b0ebd13d7f67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4b64f6a1-5d8a-50a4-a378-db84e9828000",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ff399f22-25f8-59d7-a65e-7a2623885143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:96857eab-29c5-5e77-b48b-1f87a2a27323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f14b5409-d5f3-542c-b4ac-26e543455a6c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:babc02ee-1e77-54f8-8b17-a5ec19e52b04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f3434cde-ed2a-5bd1-aacb-c02af889499b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:666800c4-e61e-5cec-a243-01e1596b9b37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3538f726-71e4-5cd3-b1c8-e2cd2d3d6451",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:14767de2-3011-533b-8e40-05b0e3bb9d86",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-tx. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7a587351-22e5-540f-91b3-ae9c18fb1deb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:db4e152c-a667-5998-bc3c-734c0387a05e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4678146d-3554-5319-8853-8fb40b9c2037",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:80b5aad4-2e36-5475-a5fb-76a6c03261c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5672b361-9084-5da2-95b6-ce7a8b7ce17c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6156fd1a-253d-5747-a7d7-fc5f767fee48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6ffce37e-bfe4-5369-9cab-8be8ff710998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0f4bd7c1-143b-523f-beae-e17cb0e38867",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f3358759-46e4-5ef8-b98c-b1237a389315",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-tx. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:865fb756-9a7b-53c4-ac61-3c519109576d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7f732dba-3597-50e4-896c-74575dc7eee3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:638eac18-4e72-5a47-b7a7-0333ffe0ce78",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d9935d4c-961a-5412-ac2b-82f3aeb10fd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0ccbf903-ce2d-54ae-8361-c8305ffaf7b0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:08b30ce5-8ed3-55fc-99b6-9a5364ca0893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8549b571-25ac-5880-b8ba-ab1fb86fb7fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:53cf0825-c1db-5b16-b378-7f8608945750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3b879473-1c17-5878-9845-5398ab0c5284",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ff105606-ecff-51fd-aaa9-d29fd1f35feb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3ae2c838-79da-52e2-b955-7d8136b06eec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6dadd437-2fc2-5192-a090-e8e7f48d36b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:45be4eae-b3a8-5311-96e7-d9c35dc2caa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a5e9dd46-18d6-5b2e-af4b-56ece5a3a6d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8c85c73a-d654-58e5-97f1-b24d667b6039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0b4f7551-fe75-5083-bfb8-7a3d3c0f3b81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dffa0556-9399-5a4f-b8de-b3125528f5f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:696d911b-7475-56ac-8d34-2e0ccd9cc507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dcd8376d-a5b7-55e2-9812-df29778b252f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-tx."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.3.37-tuxcare.12"
    }
  ]
}