{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:75568630-5e5a-55b8-9f00-ab1bb1aa7180",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring",
      "purl": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1",
      "version": "5.2.9.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:95a9cae0-d5aa-58aa-81be-ecd2e60f8fe8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c282f03b-9855-5a5f-aa0f-57257a834ed7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36fa876d-5c1f-517f-883a-5ba3ad1a061f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ee6a728-75df-563c-a2be-acfdc03f5802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3198c56-8326-5d21-a5a5-d31c01379c36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d191c0fc-a3d5-5792-87be-9976af4e6e93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3debc685-d725-5e8a-a182-9f56e883de72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3dc96e99-cfc3-53ee-b3c0-9cdd3f0b4023",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:21f21386-aa9d-5732-ae0d-beeb710f238d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5a7617b-a919-54f5-a2ee-f9c91c69e0c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1c839b8-acc1-5782-ab13-10dc31e0ff1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39184998-53c2-528a-9977-6c07400f8e22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c55c752e-2133-5684-9a60-b968ea17ce9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18774d56-c1b8-57c3-8e66-834fa8426cbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:488d50b8-f651-525e-94cc-b9bd6915040b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cb12d505-16dd-5038-b153-19a45c44e562",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:679d76ce-4d39-5032-8b78-41f4257d771c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b0bdbe8e-c092-56ee-b059-0565b33e46fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3c7bb45d-68f4-5933-b91a-605c9f87acce",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring. not_affected \u2014 Spring Framework 5.2.9.RELEASE is not affected by CVE-2024-38820 because it lacks the vulnerable code pattern. CVE-2024-38820 fixes a locale-dependent case conversion bug in DataBinder's disallowedFields validation that was introduced by CVE-2022-22968. Version 5.2.9.RELEASE never received the CVE-2022-22968 fix, so it still uses case-SENSITIVE field matching (no toLowerCase calls) in DataBinde...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d686aa27-4055-5b46-8617-c04f36e4fca3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:482172f3-5b82-58d7-b51d-84c9cb75c458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d5e0e9d-c0a6-52a4-998e-fbaa5ddb7f8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:220ae37a-e066-587e-934d-5eecede16023",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10e9afc7-52cd-5641-beb8-42a7d6b47b22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3d520204-39be-5988-b6d8-5232e820e030",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40899999-276a-5188-adb7-a9e8a92984e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:92523f1e-0946-5b50-8c17-3f88fd997405",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4111803-e72e-53cf-830c-009f14e3ecf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45f098c7-1776-5cc5-be93-6ad1d892f548",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fcec043b-fd49-5eed-b7ec-396bfde4bb1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8590d6a1-380f-5a2e-a3f2-d7a7360c99d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:35cdd46a-ba1a-55dc-9206-bcfebfeffe3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bc9c17ac-d8cc-563b-b202-07426e70bda7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf9a7e14-87cc-5062-baa0-767ebdf8a711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:480e7170-595e-550f-aeb3-9919866311f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ebbef45-a207-5b53-8e06-1de6c9391b9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7edc64e7-cdd2-5796-96d5-f47e27b9018b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78e06fd5-a218-5823-a2ae-4f53d076974f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eafa702e-757c-58c5-9770-81d5b4bc47b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70670ff4-40ee-596e-9e13-1fe29feafae4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:051d0775-2fbd-500e-95b8-7ebc807ed772",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70f37e4e-9669-53bc-b72f-75317b889a96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40b4eea8-6870-5819-bd53-9f8b5dd9e29a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:550b9d9d-cbd2-525b-ae43-ef113f879a74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec26ba0f-42c3-5c3e-af0d-27b9925a922c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f554404-ba19-53dc-afa7-222a6db804c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36708587-393c-5206-9705-2482ce9cd138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d35f273a-fa29-58f2-8f1a-e99478b301af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50e6f8ed-ceaf-50a1-be8d-5bfbc0cdc6be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bb84905f-63a7-574f-9c31-e128f83192ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fccd56a0-419e-592a-9d6f-48206271a406",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7364b4f1-9853-51d4-bb75-cfd4905aa0a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:624e61ca-0da0-5caa-8037-54b11efbc4c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b19201c-f91f-55a6-803b-2cb8b7e80769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06b5c078-5b77-5096-9bfe-43720aad4213",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5aa3ad91-6102-5d6d-afc6-b51864d2f22c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f747b582-d8f8-5dd3-9609-4cf6b91d59a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc384347-522e-5454-a384-49c35e82f762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring@5.2.9.RELEASE-tuxcare.1"
    }
  ]
}