{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a076cfa1-6d5c-586d-8de1-390f90e4c1da",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5",
      "version": "5.1.5.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a8e7afed-24e3-5b50-993e-9ca42163aab3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:50734640-ec14-5ab9-9f94-2dfd43cc7e87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cf4972af-a8b6-51b6-b351-a52bf6620f15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:faf1bb56-39bb-5e4a-8df4-48d6f9cfb512",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4e1c5acb-e274-5614-bf26-f7a8db06a891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7ea28a1c-8c8a-59a6-a7bc-c424d047b1c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2626cf1e-4d80-51ee-9366-d94cf83eefbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bd165d02-e7e1-59bf-a675-a533ee87f00b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dc9c3e64-27ec-55de-9e9e-979181102580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0616734e-ac6e-5230-8c07-d03156008fcc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:02c4f434-58db-5868-a817-4c37207c71d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:58d178d8-afb1-5026-9f79-756af11e9cc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:36d43bea-72e4-51cd-87f5-56aac65e8777",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c465a26d-7dd5-54d1-a315-9665661266cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:07c4aea5-2d4f-5a64-ae6d-6a3ec0fcb84e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ebf2f74d-3a23-5813-8e33-7af6589ad5fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f9b4a2dc-2859-5ade-b3ca-b8b0a7e27583",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webmvc 5.1.5.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e25cf800-d035-5745-a326-d5c5a8250c5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:95641f9f-cdde-5030-9570-7f685e9903ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dfe85f9a-74a7-50fd-bf4c-bd3cf19e4a63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:26124529-f783-5b61-9070-dd46a9088653",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bfd50168-8528-547b-81bd-8e201aa9c621",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:83fa9ed3-8856-5463-b2ad-5fa01d7331b7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1b6f549b-79a8-573a-9d4e-05dd77f6e411",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:099c9a31-899a-5cb1-8d16-ef6bf797749a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f91a96ef-45af-50e8-bf8b-20f1004102fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3ddc3be9-e003-5c11-a188-02a60e5f480f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:72157856-8933-54e5-8171-15b1318e8d9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:39ed63a1-3cf8-5fd1-ae4d-933bf096c7c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a9720913-1887-555a-9923-e63784113d81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b0350019-2dd7-5558-8c89-d1f38bb48979",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a71569b6-a08a-54cf-8ec1-27b414fb5da2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ac4f406e-b5b6-5580-925c-ee4d0ea63436",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a8bd8d97-560a-5c26-86af-f30fe783e44f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a76db343-25c2-54ca-9b4c-36a338ae6591",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3b6d6db9-7c08-5ccb-be33-d44d72afcabb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5facb903-d8dc-5dfa-bc71-2bacac0e40ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2120df48-e7e7-5f25-8e9a-5ef16e2009de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3f951714-6a04-5b07-8bc8-d6301b000a9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d07fae17-8956-53dd-ae4c-9b2566a4f721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:216b979d-7a2e-5bf7-8529-5a678a9994f7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e221aa36-3d16-59d0-9051-e71092276f06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:475bbfa7-0dd2-5a92-8e52-99e6c9f5d847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:86ad8e4d-ead1-5192-91f6-93da3d7b3e5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5e602a15-2436-5c03-a2ba-a433fdea1fe0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:64853608-dc02-5b3d-ac2a-4c4dd6abd55c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e4f4f50c-a783-5850-b2a9-8f3966214ea2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e74fe8cb-41b5-50d3-b62d-038830ff9442",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:12f48c4e-c5c4-5176-ae72-2fbfa8223276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:668e8863-8ff4-5dc3-a97c-f72b4fdb4462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:095588e0-b615-5a01-af97-1ac635eaa63f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8c7350b8-8876-5426-b141-200e4083292d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:63004a4e-6e60-5afb-b30a-b5e039f22cff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84cde87f-27b3-5cf7-ab34-f290078f1c80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d6031e8c-7612-5d30-b439-eaffc0d17ed9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:abe87861-414b-51a2-8180-d27ee109e862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a9f8e9c7-c83e-5a2c-860c-1a3734039bba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2c57f8a6-b834-57e2-bc15-2e19a7e8040a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b814d64a-7d58-5907-8dfa-5e5c5c548798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.1.5.RELEASE-tuxcare.5"
    }
  ]
}