{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9dd33942-142f-54dc-b4c4-9d82790734ce",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jms",
      "version": "4.2.9.RELEASE-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2cab8c6d-57e2-5d2a-bef7-e136c7d8a92e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:767b9d0f-69d6-57f0-a3cc-2ffe50878345",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57b929d4-61d0-5f62-b23a-af0f8091a885",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec1aa144-9ad0-539d-a87b-ac338b2a75a6",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df3d03fe-084f-5759-90cd-2fd71610ab56",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad1f7adb-e21d-531d-a63f-27d8391f3b0f",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41875d8a-9542-51bd-8c27-d859019de257",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbddc305-f6aa-5f8d-96b1-fa9a7451b97d",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa245a45-3a50-5cd5-ae2b-535c6ae37da5",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef739c2-50fc-5822-8184-9050d9988205",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62e40601-9c40-5ac7-a6f8-29c990738928",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e19848e1-51c6-597c-8961-f65f75e99597",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b8b30e9-89e7-5348-a597-651324ca7045",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71ec97fe-fedf-5fc0-8658-b9d0f78382db",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70a05b32-7c2f-5aa6-ac3c-5e1b5671acb1",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35fffedc-1bbc-5572-aa84-60d6746efaf1",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3210cb06-3156-531c-a2ed-63ec2f96e11e",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e20573f1-2e5e-5438-b318-fa9bcac92931",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf36dfe4-e514-5a93-bcb2-ec2fe868fee9",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcd03786-4b7a-5449-9530-9d0897816251",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13fd11bb-6126-5a2d-838c-37db1ba9144d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b347ae25-1aa3-56b9-bb04-6532ec8bcf4a",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e56dbaf6-d9a7-5462-8d4e-ea9d1ccf743e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9316e072-43ee-57cc-8dee-da9457da01c7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96c8acca-4581-5efa-9bc8-3cb4087d6a8d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4da74b6-6973-57f6-be3d-ac051fc8dbcc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6861bb7-ab73-5eca-8eb1-b455385a9c09",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00488f9d-00c5-5b8f-8a94-d75c452f13e0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8fff859-0bd4-505a-90cc-df53efa46a32",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c391353e-52ad-5164-af6e-fcadda58def4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdccc1e0-e123-5191-8f16-9fcefc3f02a4",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4a189ac-4917-5958-b262-37b870ad58bb",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5102a5e4-3160-5238-9669-8147bb7984fd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f92b96b-888e-5577-b070-febcd36b4954",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:890309e4-ac7a-51aa-89bd-bab17561831f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da35327e-197c-542e-97d2-3253d0dc64ac",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b4a1e4-cd91-5aa9-8923-d4ff9d51994e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5d20079-0742-5380-aa9c-89555863de26",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e7f436f-4ebe-5670-8520-73b4441e7f48",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1101b4b4-6551-5c82-b808-c8da877d6663",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d5f639-fa20-536b-a1b3-f51b7cddc28e",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d839ab1d-9531-54f7-b55d-33a147aa9897",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a43da80-8d21-53ac-ac4b-5c3e7d884bf9",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ebaaab1-74ee-5f33-a1fe-e3c6e8c8c653",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f0b7e6-ebe6-5617-9c5b-8800ba7eac8c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:892cd1be-06fd-537a-8118-4cde7380f9fb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.6 of org.springframework:spring-jms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jms@4.2.9.RELEASE-tuxcare.6"
    }
  ]
}