{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:95a2af6a-7181-5779-8e7d-64e2e95aaaad",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-beans",
      "purl": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6",
      "version": "5.1.20.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:04de659b-2f9e-50d7-9f26-07729ec7ece3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:60e78247-dba1-5a4b-8383-c6e7a110c5c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f6e80b7a-7b84-58fd-8b29-da0b1e5c123e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe56bd0e-9d40-549f-9748-1e6639118dc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:67ba3cd2-f198-574b-aff6-5e2671f13623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ec5c7fdb-7136-54fa-abcd-ac30c44358e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5887efb3-28a2-5dc5-945f-3ecdd94bfff9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:168cce84-c17b-5757-bbaa-c46a1eb207d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e6a72b21-2b92-5e2a-9d06-4147437147be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6c01d42f-ab63-549b-8d7a-de7314241445",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:826c6487-4b72-5547-99b3-dc0308cc8ddf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7fe491b1-b509-5376-9060-6017be3f8ed6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:757f5768-4aec-5467-9753-848f1ff63558",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b7faba40-3dcd-5c93-8cb0-4f58022b217b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:88aa2f8a-7d39-5632-8fde-24dbb131cc6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d61b8f66-9cda-5777-bc43-b7e8d6da7204",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-beans 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:841e7ffa-6313-5e60-994b-6e4bfaa08499",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9f3b4d8-e529-54ee-bedb-5f21895e2eff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0e1d2f5a-5663-552a-be85-0fdb967e8569",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0da0fdc6-a058-5a4d-9007-d2f6ff86bf01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6bf2d0ed-c300-5ae8-bf0f-96db031a99a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:03282db9-0528-55e8-8e75-f7b00c47fc80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c836548b-442c-5774-9872-b0da01bfc19e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3d7ff90f-ea6a-5141-b2c2-746581362072",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:472c5585-fc9d-5e92-a3f7-852a4e8ae541",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b85521d5-3acc-5345-a0ff-7f1eb420a435",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9c746ec1-6f17-56c1-baec-ed3586c5ae87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6f96017b-687a-5171-840e-07df16c28aef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:32c86690-391f-58fb-abe9-851c830d1ce6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d36bc595-e423-5a55-9403-e30f9bf2e87d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f0b5b69d-20c0-5aa2-a14a-1ca87b2b8e37",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1dce77bd-67d2-514d-bde1-929d67c0d90c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:276fc807-886d-5699-8b02-102ba2668976",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4c36e0f7-384d-5b53-9092-df139cb389cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e9bbfb25-1c87-55d4-a7f8-062ebae5ae77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:191adb92-e806-522c-aeec-c7f1a82f2ed9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e6d9e9ca-a33f-54e8-ae96-e154eb37abcf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:508d5414-1939-5010-9e65-305297f98c3a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8ac6e702-64d1-52c3-8629-4b5bf4f89e22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:84387033-c181-5b60-9bac-9fc4683d4018",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:83110561-d80f-502b-9314-6ca92ae4be14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e44adc24-7c51-5ae5-842b-4f2d4766406b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3f0ef454-44a9-584e-9bf5-8597881693a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:817cfbc9-daba-5453-9ff8-12b33bebc39c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c3579645-e8e2-540e-95fc-f77351e94c76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8019bfcc-b3df-5744-9e39-6e31addc96bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:845f944b-2f17-5576-942f-d97813bc8da3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e1877c0f-5a0b-5b6e-94a9-c09b8164dca2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a94e24a8-87c4-56cf-9cca-36e040de0ec3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2d8959a9-09bc-5d14-a2d7-1569061c6f52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c4af50f4-6f1b-56e0-a7aa-96f1bf60386a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d549a84d-6abf-574f-b72f-ad59a6f2bd08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6d90d374-b9b7-5deb-b604-1ba84ded42a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:624853ef-5361-5394-803e-25059d7f26a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:44ea9d56-6ea3-5acb-a560-d2d350d03306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b1aa269a-a16d-56f5-bdc4-5721ad156bbf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-beans."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE-tuxcare.6"
    }
  ]
}