{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8a6c4479-2d32-5a82-befa-fc8eb68a8a97",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1",
      "version": "5.3.13-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0cf0c6a4-dc0e-546a-b23b-efbb3f85ac89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d26b4203-adbf-5af4-b2bd-744ab8053b71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06f6a12c-1099-507c-9161-7aaf050e6a14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e4aeb6b-9e45-5dbd-a56f-10da066a78a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2429a399-1ad8-5844-911a-27268a2a4942",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86d2c9bc-f22b-5d43-bdd6-3619f2d0d47b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cfc40cba-a4b8-50e6-8dea-d563e1996141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0361b74b-94e9-50f8-8c62-d48c1acd52cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9b9aead-999e-527d-a5fa-1d69e4c9701b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9feb1ed1-9c1c-59e8-8cbc-8ad8d7906d0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cb00a963-421c-599f-aa14-024032684ac9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0c72225-6398-54cb-a63c-7a249bb991f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c58496f6-4141-5f1b-8596-74b257523522",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad599d85-8b02-5b28-9d39-2b98c5a14ca8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1dcdbecc-f19e-5d71-975a-9010929527e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:df9bdde8-3085-597e-a671-4f6ff23b8746",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2bffc4e2-7fa2-58c1-8df1-cd602d8fa3e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:103771f7-61b4-5550-9d9b-11e74966f534",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.13-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 Version 5.3.13 is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() bug in DataBinder's field matching, but version 5.3.13 does not contain the vulnerable code pattern. The CVE-2022-22968 fix (which introduced case-insensitive field matching using toLowerCase()) was never applied to this version, so the locale-dependency issue that CVE-2024-38820 fixes cannot e...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b57733f7-d295-5d4c-a001-be00523a19d1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38828 does not affect version 5.3.13-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 Spring Framework 5.3.13 is NOT affected by CVE-2024-38828. The vulnerability was introduced by an optimization commit (gh-31834, 0970b1dc7a) on December 13, 2023, which post-dates version 5.3.13 (released November 11, 2021) by over 2 years. Version 5.3.13 properly allocates ContentCachingRequestWrapper's buffer using the contentCacheLimit parameter, never reading request.getContentLength() when...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8741af4-51d5-521b-b0df-062f2f8ed945",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d38b7424-b812-5f1f-a780-688d3e2ea754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2d44d2d1-15d5-5140-81fe-7d0be4fabbc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb5f4e18-baa7-51ae-aa1f-1e39e1b9511a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9abe67f7-742a-5c91-b946-2b4a8dc080b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:904808f1-524d-5556-ba3c-a76ff08f98b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc3f34b3-d927-5be0-aa9d-20b885618c25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67a84108-9618-580f-ad66-6b72c230bfa0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e757f9b-f389-546a-a1b6-5f16141aaae0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73a99fee-2cde-5c3b-ad11-46cc00e54239",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:effc40dd-f9a0-5ab7-bc63-0af8e75c9d96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a43a2ad-d624-58ec-980c-1a5a056cb41c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4951fc44-97a8-511e-9612-ef626f646487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b904b87-4002-5d7c-ab68-53f4222c10fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba34c476-88a8-5a82-8e97-b8382f459f8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e7fd142-34ef-590c-8802-d622c2eb0f24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c40917be-97c6-54c2-b454-54cdb0a2376b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d85e1c5-a167-566d-8521-64e3a4019381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de8bbe63-324c-56d7-87a6-e8bda10a35f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c86136b-f082-506c-b831-599b089a5d5c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:588f0bfd-44d4-521e-9d73-3fd4c645492d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b52e79fe-9ebe-59b2-9338-582af75e93bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8c03a2e-0667-5c9e-b74d-0f7d8b12fb29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c853855d-945f-5072-813d-0e27168f6dce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:03f5476a-c942-5ba8-946c-e72af76732f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:edfa6e7b-8e55-51da-9f12-0b8fbe492c5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e7bae7e3-c043-5f18-9fda-7ebe0dfa8d5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56f9825f-91ec-533d-ba03-11818a161c31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86283808-6acc-5089-883d-5247808824bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fd8b430-84fb-50b2-8c12-48c49f38455a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28e10dd4-c0ea-5d98-83e2-c3cd6b22a254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:533c1f77-c1fa-51f5-a454-c26373cde6c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b688d80b-b118-5424-94cb-17123e8af84a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a06b2a00-b3cb-586e-8fb8-bf8e9ab3746c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d859034-d5f8-5fde-832a-e70ea6badf3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27ac5244-6a87-566c-89fc-8a08f09b77f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d0018fc7-3933-5af3-9c11-08bc54664638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5b04d34c-3ee1-583f-8251-df52d4d98590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d6b5d3f-6153-55f7-8f8f-8045c54f5974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:23b2e7ee-eb24-5bb2-9da4-721a2d582eb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.13-tuxcare.1 of org.springframework:spring-core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.3.13-tuxcare.1"
    }
  ]
}