{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c3a88f85-3dff-5f1f-999e-653f8a94690f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-messaging",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1",
      "version": "5.2.9.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6dbf6159-5abf-5599-98f4-1a70b9e3ef45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7867d849-a69e-51e0-b8d1-0b89d0deafe8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2f8d549-355a-5563-870d-40d6aea2e80a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94134ded-f26a-52b7-91be-15bf7e776c37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:323cc68c-9eff-5b7b-8f3a-2962ce6eaa08",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7033e23c-0768-5e3f-a68d-da9efbf6e10b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b9c43204-6bf7-56cd-aac2-327a9b4e84e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d85fea63-7768-5608-9cd8-e88717b77a1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62390f68-b74d-56dd-85f8-4d38ee64a570",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:43edf757-3907-504e-852c-2e4a676ccef4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:921dfa3a-65c8-5e87-929c-0c3d80a90036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69be5b40-2055-57ee-8d61-a06b179a63a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c620589c-06ae-545d-8569-3b6f6ef97f2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3785a369-8602-5aea-be83-b7174f78c5f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:027e3c86-39fd-57de-8cbc-51668601d745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f440711-a524-5146-a955-d6de4e0b20f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb363432-2be5-5611-ab80-c25da9175ae3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db6ebf6c-643f-5c4a-b446-b0fdaaa23bb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8567ed6-2dbd-571f-91b0-4e5afadb584b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging. not_affected \u2014 Spring Framework 5.2.9.RELEASE is not affected by CVE-2024-38820 because it lacks the vulnerable code pattern. CVE-2024-38820 fixes a locale-dependent case conversion bug in DataBinder's disallowedFields validation that was introduced by CVE-2022-22968. Version 5.2.9.RELEASE never received the CVE-2022-22968 fix, so it still uses case-SENSITIVE field matching (no toLowerCase calls) in DataBinde...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e3162af-8cc7-5c78-8ea4-44313769aa2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae6852f7-8c3e-5514-9f68-663969824b9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:222e6593-815b-5dbb-a4c5-b9a8e5662e58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf81f5be-ffed-5d6f-a898-a3160b51e758",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed9c1317-6d54-52a9-a252-73c9e4e3172a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:985fdc0d-da6a-58b9-9448-5ca5b3bd4645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9d7848d-c55d-5a95-9bfb-282408303873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4c4e69a-cc69-5911-8be8-0e71725d62c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8b42d96-0b7a-5cd2-8b93-1df8d5aac088",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71bc51ab-6332-5179-9e6c-daa8b00bba7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53981d7f-4e4c-5f8a-991a-28e0e05c41ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ca074dba-68cc-50f3-bc0e-e2b6c10addcf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e56d651f-a05f-5257-8ce7-52f3405ac118",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e2b4c95-9b5e-50e5-b808-234c23c11075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de086c51-212c-5032-aa4e-3c8057565c74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc23a819-0b23-5f29-8097-0a65ce81edf5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50fc9bef-06b9-5c61-9183-ca65e0ce7110",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d22e32f-e2bb-5c3f-b943-00aa709b097a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34e655cd-1437-5dc8-95bf-3dcebe738a8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:374d6aca-bde1-54c8-90b7-357976ff0cb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:03faf2db-60ce-5d80-823b-8446be20f451",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27be1ce6-060b-5b5e-8052-3e179eb4846e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:374b3236-bf99-5710-940e-9edbe73bb048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3998ef6a-93fc-51ac-b1ac-c0bdaef458f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fdb931d-5a0d-5c03-a2d7-6d3778cff57b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2531b563-05fa-5f60-95e6-8286e4af6ecd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf2a9ab4-6c17-5563-9462-641190920b73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:227b07bc-ca04-5fbc-8b1d-9dc379349c65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16ef7be3-7e73-5c91-b8e7-15c5c9825c88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71cc0025-8f20-5ee8-b08f-90b229ae6755",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7f9c9ac2-ae43-550b-8d73-d63937a3554b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82d2f4fe-a801-59bd-b482-ccb3b4548012",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e59a5dc5-166e-5a5a-9e3c-28c953d38da9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b4c2d0a-4923-5033-a83e-3d645fa41acb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e84ce021-1412-5f9d-8d07-1a581e939c01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eeacde68-ec94-5709-8615-0b38e4abcb18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70609e30-9bc2-56be-9f66-75a66af3e61e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38a1738c-aad1-564c-a8f9-b43f7fb7c2f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55948301-4c53-5d40-8291-3ef3105a725a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.2.9.RELEASE-tuxcare.1"
    }
  ]
}