{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cda8d153-292b-5c76-a740-0111666ac969",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:14593491-ee15-560e-9873-5adf0b7cb959",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:711e6933-a455-5b8c-83d5-b1dc4d01e605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:69565d23-c847-51ef-a6b5-b874203ba0cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2db2512f-d20d-5c5a-b9b2-67b93bb52e54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e1a96d2-fadc-50e2-9f33-76e1e0bf9640",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eab5701c-054f-520b-9869-e4a3472fb6a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4971910b-20e0-5faa-a22f-0a960bf9d1e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54441d7e-a128-52c4-be66-e553e1af35ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5a6e8dfe-4b52-542a-a714-f77bc6173ba9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d94e4c1-073b-541d-b289-09196d464e38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2bb7c96f-6178-52a8-aaad-f157d3dbb10b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:48326e0a-18e0-5671-bbaf-bf8533466547",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f65a077b-7199-59b8-9221-f7ffe89004cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8e6522b3-5a19-5ed3-bbd4-9cefab1a0a37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:242e9361-e915-573d-a09a-b3620215fdaf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bb6a0d33-8b22-533b-9394-4d2c26a21e03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:05c1bf34-39f0-5ca0-b412-2844b4c3e355",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d1995dfa-e00d-50dd-b79f-1db13060b812",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d924949c-3c77-5d15-8b31-9cfcd6892475",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:edb8ad7c-d286-5894-a06e-f752fc89e653",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b2e7f544-f6ea-5bce-a32d-0d635d363496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2257103-c26e-5241-9d27-98f8c52555e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e6e3c898-1b68-5918-bb63-31e7e43c0218",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cf820c8f-78d4-5762-b452-a7f720028101",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8af4edfe-a81b-5e39-bb74-cc2979661b41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b46b0f2-7ea5-5ed6-911f-335925f44a7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0db4e2e5-1d00-5d26-96c0-00d04f8f52a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4e1ff849-a5ca-5459-9e9a-4ac55a979ce1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9fbd7919-2996-5712-931c-fd1f49eedec0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0caa43f9-5791-5f5a-9004-9ef7a4d62e87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cb48d491-2250-5c18-a17f-734c38475f84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b210827-b7fd-5ecd-b39d-b91f232c390f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d5753da-7690-562b-bd0e-339909219d1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c274d329-c248-51e8-8998-a1bc24b4606f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:06a194ee-e26c-50ad-96e3-bc7ee191ab87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f3863452-1d3b-50bb-b26e-a633f7e87a99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d28814c9-68ea-51ad-afd8-f2568c6fcef3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:532fbb5c-0518-50af-9c01-ab57d7d9c08d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:44262082-24c2-5bca-ad47-67e3c633d123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:01931578-a795-5106-a7f8-4afea6038e88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4f3a1d3c-b380-55b7-8d33-4f0064ce6949",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e75a28aa-a8d7-5f8b-ad8a-ca8c0dd9aadf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5474a99a-aa7d-5223-8759-49f804dbacd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:81cfc15b-53ad-507b-a0b9-3d19d004525d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c5c457f3-894b-51af-87cc-44c8cc939c37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a066e594-ef75-5b48-9b05-51a6acf24c9f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6c705393-79ff-5fcf-99fd-f46a4198dec9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6e4fcc62-1e6c-547e-be4f-cfd5c83719bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c25c41e2-826f-5ad8-8bd1-7e2041a500de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e1cdfc57-efeb-56c1-bde7-168a24252533",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1a9048e4-2559-53fc-9dc6-341537f85dc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76d58f7b-d447-58ca-baba-4d97fd45cd02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b9e9e529-0812-5120-ab31-e9dad9556507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1f76af92-382d-5c30-9f39-28bc7929b336",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b807a486-6ea3-54ea-acee-17e46d90f2c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e24fedc1-8ebf-5301-a731-792340e4edef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8e7c20ba-53b8-5ca1-befb-94c3f548de56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bb8d9cc-a8ca-5fd5-b56f-c1de838b6ff5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff3f1fcc-2a86-5a18-86d6-fdde1f3d021a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:019542da-1cc0-5325-825a-27bb2b1d75fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e13bb78-0334-5078-8117-52fc917f15f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.6-tuxcare.2"
    }
  ]
}