{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f481be6e-16f2-5705-8662-23af3c131b23",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jcl",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12",
      "version": "5.3.37-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b128bf64-2d57-59d4-bf7f-548419c989d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jcl and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b6dc8ceb-bef2-541a-ad09-cdab7d9b3db8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cfe326fc-03ce-5026-b8c9-45f744825575",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:42344b3c-fb85-5d21-bb4d-77e4ec2220fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ba044aa0-b4fd-5fb7-b629-d8e256210768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ed4acb89-34c0-5204-9160-46ec5a8385b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3e9ab39e-2cd7-5b0c-94c4-2f2b03fd1600",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ca1d97fa-870c-5e31-9200-0cc0a9001bbf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4f53ea31-e51f-55f3-8f1d-1d6361403cf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:88d90dd2-b803-5141-9182-b6b28199eedf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:601df2c9-852b-5393-b8c8-27bd2b1a721f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:022d365a-26d9-50dc-8aa0-472e816b5a4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fa343575-8e79-5bc5-8aa7-afa7b36b8adc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d9ae84e8-0a7e-5620-9340-35e8cb8bcc61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:038c6805-9559-5cad-a376-a26efcc216ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3fb5102b-8457-5ea8-88c9-dcf25eb13c72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7c1bcfe8-c723-5a6a-8b13-c029933cb747",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bf21100a-9388-59a3-98d3-aa2cc7899e58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:89b0cc61-9bb4-5479-9a62-2405e210e579",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jcl. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4b349317-08e5-5fb1-b700-3083865fe9af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e566e010-3c1b-5fa7-bfbc-8130f4db5455",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5d5aa995-0233-5fd6-9ea0-1520cbb8bd83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ba990111-cd91-55cf-8619-d1a9b4d3dc5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e3b89798-9f5c-581c-8c65-2d0e61c849e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:946dbe88-0d71-5495-98ba-1142c820c8b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:aa429544-9c36-55a6-b8bb-73ed90c4f01a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:37b381d3-8aaa-542f-a24d-7d559e364448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:032c3dd9-e3be-5abe-a4a8-975b3bc4d021",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jcl. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:729a64b1-f648-5e4a-b3d8-a8817f796127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ec001e54-1af4-5d7e-a589-af43c18f5f12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:85003833-13d5-594f-adf2-fc080fe48eb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0f232839-f818-5e4b-bec5-22951c7da882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e9106514-be75-513a-bfdd-4cc7c6d35612",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.12 of org.springframework:spring-jcl. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6ee18943-d5a2-5acb-9546-1ba660a29c75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:80c1e14c-5a52-5ede-a7ae-c1d7eb1a546e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:79c8789f-ef41-514c-931c-a78f03f4257d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8b389b32-b36f-5a90-95ba-e27389be0529",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7fe8f266-250e-55b9-b870-1eb23ac95e37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8a17abf2-750f-5d0a-8473-9e2ab9b58594",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2948424f-dad0-5d85-b246-df11c3aa0f7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c44a3b79-ce7a-5f6a-85af-a54a4d4f7e80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e52e1eba-c45b-5ead-8e6f-a190acd29d3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c227a640-bdf2-5c02-91a9-7a18305c0d6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7b2df752-5f39-5ff6-acdb-7e08681e50c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:11d8701b-ce5f-5217-919b-8446173174d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:07febc8e-8278-5b1d-bf56-67570e14ecfb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7aaa51e6-8016-5254-af8e-0229698d19fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.12 of org.springframework:spring-jcl."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.3.37-tuxcare.12"
    }
  ]
}