{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d936b70a-435b-5ecc-83c7-84c18ebeccbe",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2",
      "version": "5.3.20-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d2c77aa8-678c-5c25-bb39-8fd1aa074119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7580ca56-ea88-5b71-be6b-1dd43321e8fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:248a2541-63ce-5eee-a16f-10dfd2a4c4c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:35e2ec65-0b4c-57d7-aa52-d140b5b8fdc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7074ef7-9b12-57f7-9212-77058d1a981d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a7b7069-09ff-5f4b-90e2-c5dfab356e57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fb91b67d-a39e-52dc-a9bd-4d5375a837e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:91e63e9c-3d7d-559c-a87c-8debc97b0d42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f03bf3dc-903c-5b9d-8b5b-f0ed09fea5ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1bac28da-bec4-5f30-8a51-8caccb34c069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:78bcf0a4-1149-59b8-b2b4-edfcc2e1e962",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e2c08ad3-578c-50e5-b3da-8822c4c3e75d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da3d316e-f020-5043-9367-43e7b641e2c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:993b201d-34c6-5428-8327-debc2f74652a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1840a239-bfca-59de-af2b-28598b0b57cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:05f356db-9794-575d-930f-c0bd0e2566bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a3a2294e-ee53-53a0-bffa-1cca87e35d4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e4bfdac-9011-5d77-a86b-e69a2e383df8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:964cb04f-64dc-5e33-9c27-8b8cd6a8f179",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c48dadb9-34fa-59a9-8346-764c4bbb507f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:533c6bd6-2616-555f-838e-40ab58cd408f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:296881d6-4031-5dc3-bb95-71d583277999",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3a55291-9aa7-5d50-863d-6f351c89dad4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4fc4f4b0-1e10-57e9-a02b-6ef2551343d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d65745c1-ccc7-52a3-ae15-3ed793442df7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:deb14e33-972b-5f5f-9201-db2b47f17850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4914cf27-f693-53fe-a791-67bb23f204c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b50e7676-b5a3-5082-9b50-e8f549028d5e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0d109c5f-af1c-5184-8ef6-864bf783e7ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:996b7d28-baf7-5fc6-b048-a0fd3d2d456b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0ad6f946-ec9f-52a9-afee-1306c6a8b33c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:392fb0cd-09ae-5df0-9a21-2cf74bece185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b4cb9ad-a258-5131-9dfc-00cd359fd1de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b1052139-fcb4-52c1-9e21-9d0150d47123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c00cb499-e2dc-5d05-a707-fa9f09dca0e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8021b365-84be-560b-b1ab-1858bbe62bd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f171fc72-8521-5f42-b8eb-0831fb913aea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8411ae89-e16d-5008-919c-f78b13a22625",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:51eaf081-8ba2-5b16-8e0a-d4d6264ea375",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fa325ee3-b7fb-5111-bc3e-9b21829c8f61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6ddf65a7-5b8b-565a-9ed1-1f443893001c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3862d144-6bed-5a14-8a01-a7412db79b1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:488eaf88-928e-5fa0-8f9c-7c42baf8dacd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c07f15bf-da57-5b42-8cae-78254e640caa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d743aa5f-1c4e-5f9a-a40a-da2d7daa6e86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45d4bab0-8a9a-5eec-aea9-20cb758ec2b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6a2ee20d-0806-5b51-83b4-23d9b32616bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a234f54d-246a-5754-92a2-ca0e6fbbca3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d0fc53c-ac14-5729-b7a0-eb042def2edb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:605c5f68-d3d6-511e-a888-9a41be17dfe5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67de649a-2927-5970-b39f-a4572034b347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f8a0fa84-ca2c-5f0e-97f8-ba4e38ed3d5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b60a32c1-5bcf-5b3e-a4d4-584d4afabef4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.20-tuxcare.2"
    }
  ]
}