{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:85ee59dd-d35c-56ec-acab-8ecdfc2fcaeb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-core",
      "purl": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:af4be2a8-dc3b-5a50-b8b4-983989a0e4bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b64903a-6f9d-5cb8-8423-fd6b7e212f10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b629339-846b-5bdc-8502-741bd00c8893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3815f43-63cb-5bd2-8902-d75b98933bbc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d7e103d-77d4-51b3-b9d1-fd3aef5285ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4a16a45-5157-53c5-b952-7fcfbf8a4c8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79bce527-e985-5833-9f70-de7eac755df8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1a08a79-6ad4-5fa0-8e9e-55b39f4c8b49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e35a9370-fe19-5126-bf23-0bab6e59fbbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c984b2c-921e-5546-b5fa-0af4165453b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:231653cb-1eff-5b6b-8a21-2af801f1720a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89ddc652-3cca-541c-a62c-ced5c9a99b2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b428ed5-a3ca-561c-be26-1029c8ab4a0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78d945f2-acfa-5c84-922b-2a18aee3483e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0dce69a5-2d07-5d92-8c57-0c6ec17b6cda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b9ccd92-a9e3-524c-bb8e-8025d0d918f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd1bdc57-341d-5dc1-abf7-df6de592e5fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8341126d-fe1c-5a49-a1a1-0fe37b9bfe10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1fb7a94b-7bb1-52e4-ab62-e5d47562b638",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e94e488-9dd9-54be-abad-f2a4f0365a1d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-core. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5f20ea8-7571-5c99-8207-40cc0e2f94dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cb1a0c1d-00ea-5aae-8559-bfa33be474b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8f6cdb6-2cef-51a0-ac3e-4717620e05ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f093fca-dc02-58b7-9d8b-8b7617fc55ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b6f4ff7-e98b-5c91-874d-70fa4aa989d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:47fdff5f-5296-562e-b039-18470ce9c23f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e3abf73-57e5-565e-a3dc-f729c03ce7a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a9ce4dc-bae1-5076-a4d3-b8253b498a7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:457e5e7c-924e-5dc8-8216-7c9039dcf62f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ac887fd-25fd-5793-be5c-85af9c3a06ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57ac3267-b962-5569-8e26-1ca84ae89fe3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dec0da0a-3b5b-5233-bde3-be20816abfcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f05cf01a-1938-5049-ac6a-c3c9c4e2ccb1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf0772d1-5cee-5f84-bc8f-ac29e167f7c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:450c95d2-cb9f-5a66-8fbe-b3498849bf4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bcbacd44-e41a-5f58-9831-2522a5443272",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed939d06-7d51-5c7a-a3da-3177ebab01d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4870554-7f32-5a61-a55d-3d76dd71b518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:949f0a37-fdc0-5344-92d8-4730142de8da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dd03b75b-9e19-510c-9072-8d3ef02173b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c00c265a-9c1d-5a82-b85f-85de30356dc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:84e03155-ec01-5ee9-8c27-d9225fbb895c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:665ecc05-4710-5742-bd04-2ad94fe1a140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81b956ba-0ffb-505c-87c3-f0f137b7b4f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:281af07d-cd62-5406-a0d4-63625e111238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba51f74e-309e-5692-8a9c-2fbfd9731a69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c2eed9f-38bd-5ed9-ae3a-2c878a2aa5b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15a62202-434b-576b-beaa-97591d8fc5e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b059a74-b567-5ceb-a221-36100377328a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9709e682-2c9c-570c-932a-0b3ecf289e52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50f8987b-8cc9-5eeb-b1c4-d5127672ec47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38f89ebd-f1d2-5a67-8c5a-99ad8208a921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67af870d-2397-5f4a-ac8b-b009d12e899d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c90178fc-1a91-56bc-8e9b-64f937949779",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26900c43-83a9-5410-93e3-5afa924cca17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:386a9f22-2656-54bc-9106-dd672dfa459f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4e5890c-1cdc-5701-94c6-3abb5be9e50a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-core."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1adf578a-b9b1-510d-ad74-7c35479ff2ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bbe63e7c-2ac2-52f4-9f23-9ae5294ec091",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef74e571-f833-53f8-acf8-341cedc23159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39c6f3a3-a9bb-56ba-a51d-244c63648c49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-core, and is fixed in 5.3.6-tuxcare.2."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-core@5.3.6-tuxcare.1"
    }
  ]
}