{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:623b2ef4-bbd1-52ae-a39d-8c3eef6b1555",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6",
      "version": "5.1.20.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6610a021-2c97-583d-bf64-291446b668f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ecbfa310-56e0-5ff0-b3d8-0da2e526edc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d77d2b39-3115-5a31-9aa8-79f5f4feaa38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a47cfe61-1220-5be7-bf1e-723284f9585d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:37465224-a35b-546a-9175-65a913ddc6c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3b32d835-d187-53e7-b0a3-6122b654b71e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6e4af46d-3e34-51df-9863-02078711639f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:75f53cbf-cb19-5ae6-975d-e336e84252e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:30544c71-43d7-516a-93e0-76400618e1aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8425532d-2658-5c49-be83-108876f4b8bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:82923485-c720-5ad0-bc14-a52244d66049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8f2e423e-7e01-58c0-8c59-e3b2241b51c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2f301f2f-b283-5bd5-b6c3-ec2797912d57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9aa171b7-b63b-5677-a4c0-866efa9d8e7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a950ef60-15e6-5fd4-b0af-41c71be03b11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6c350550-e8cb-520a-9ab3-fb6de06eaa66",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-oxm 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:42bf8bfe-2ac0-5e20-a85f-3ceebdebdf99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:569c07a4-23bb-52d1-b65b-5014f1723025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2e7659db-3584-5399-a86c-a499cb7ecab8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:92176907-4ff9-504c-9c95-c71b73f3eb23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe7ed711-ea21-5dc8-ad74-65364a4e7b2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4c207398-046a-5f09-9591-875ec6d4a261",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dee2231d-2776-52c4-b33e-8e65126cc964",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:66f0e320-9096-5f4e-be49-669d9595632a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d403dfc0-0f34-565c-b961-fbe4fe030d3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f598a67-3f1b-5ec6-8d7a-ab8a321bc0b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:48fb90f3-9ce9-5d0b-8023-95db8b0e1ee9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4dd23ad7-3d6d-5eba-9396-b036c26ab313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a2c09ce4-476c-5ca2-9f40-e165dab4489a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c1d71bfd-1ea5-5249-af8b-db7bbbdf22e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7c6d822b-c80c-5ce6-8735-f854b5e9c46e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e1631436-81dc-5f5a-adb7-f769088c4bda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fb85ce23-c908-57c0-9598-75923da12768",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5f0d427f-0a3d-5a22-b3d6-0819ce0ab85e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85b8ab23-5e47-582c-9d16-363075997ef8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d8d53724-f622-5014-8960-5e0fb40bf32b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cba3cce1-ae06-5fae-8132-9c3ad3599c5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4d4ced37-e5f1-5587-bd6b-3bef660645ef",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3816aa64-ef62-5137-a94b-70d3a4e1b9d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4f4d9b19-7866-530f-812a-9e1dff2b6b86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aa42c545-8e22-5dfd-9d2b-0b30cd4ad43d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d3d9792f-9f68-5582-83ad-3f4717f50703",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c3bf4d94-4682-5d1d-a63a-efe6f0f5b85f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b7b702af-1eb5-5201-98df-d7a4be679353",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6d0ebc8a-ee31-5754-a736-188f8f634347",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:af1d7e5d-8cc7-5b1a-89d9-d5c5ba7c624b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:731594b4-9503-5967-b660-f86da77037cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:db641cc2-25f0-59ec-9ed1-633f6b22ee06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:06cdfe4b-ebb6-55e7-b736-9fafa6dcdaaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ec32b73e-9d13-597b-afd2-1a37b84d7a3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c128dc14-83db-5919-845e-b46f204bc49d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f6661790-eeb6-50fa-87f4-14c74a0d7ce4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9687745f-18b5-569f-939f-14a4ebe4ec36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a42609a4-b3fb-58d2-80ba-05ab79de33b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8e0c4ffc-c8ec-54fd-b87a-99ae4dc893ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9bcec6d8-1cbd-5a0c-8f4b-758d1a9ab9c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.1.20.RELEASE-tuxcare.6"
    }
  ]
}