{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c7a4b624-cd07-56ac-b5da-025497ec724d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1",
      "version": "5.2.9.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e522a35d-8f5b-5b25-af98-0e500f0fa958",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d3e6ef0-216e-5dfb-a54b-0cf666144293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59589cb4-4423-5a22-a3ea-0db398298d01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3b0f1b2-fcd5-51c3-9fc2-0f50f919efe9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa5d7e35-e71b-556e-8c02-163dace1d81c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e50bb287-d410-53f5-97db-fb108fb856f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a17351e-02a7-5518-b099-cdf8e7b56261",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0aea9e2-b9da-50c5-af0e-fa5f92c8a28f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2a3086e-2946-54c7-91d6-09dab527da8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a90c35c0-65f6-5cc2-a41d-f16eb9cd58d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6873b21-0a6c-5eec-aaf1-9e49cb5e2b55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:00c73ba5-5780-58ff-a746-fca86921d789",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33dd4af2-7d5e-5c25-9b4f-16bda7fa12e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fa3badd-b4f9-53bb-bc38-d8989b97d266",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c7ee8bc-0173-5a88-b993-eb316eed4098",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd423ae8-e316-5947-805e-45b507427fec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:864323b7-8d66-5081-9dc9-a81bf3812825",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4bfa017e-519d-5402-b1a5-5f320862ab07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac458224-7075-5a4a-b9fb-1e519ab3ac00",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 5.2.9.RELEASE is not affected by CVE-2024-38820 because it lacks the vulnerable code pattern. CVE-2024-38820 fixes a locale-dependent case conversion bug in DataBinder's disallowedFields validation that was introduced by CVE-2022-22968. Version 5.2.9.RELEASE never received the CVE-2022-22968 fix, so it still uses case-SENSITIVE field matching (no toLowerCase calls) in DataBinde...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02922404-d7d7-5e4f-8239-fc4491114fc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73eb2d0d-adea-587f-92d7-a352029cb138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87afe1b5-fcfb-5653-8ff8-67218363be03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1fa8b44-c549-504e-a387-72986fc516a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:98cbe60c-6621-5ee5-87fb-55c4f2c165fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78679a23-9ca3-57ce-8f81-9df93f74b302",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9ee554a-8d9c-5785-8347-70edb86c06a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ed10d8f-66c4-54d3-8046-10d962ae00a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2d6bdfd-f33c-53ed-b7b9-014290f1f6be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c5ac863-c5a4-5f02-9bdd-741ac29027e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:22118430-3d75-598e-a582-6d5f682e013a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69efd1ec-aeee-5058-9894-a4aac8db8612",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:140bbd88-5079-56ef-86ba-9356d371ec8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b898b38-3541-5f87-b325-9d9efe8cd026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bd5c29de-3bb6-51b7-8a82-bdb357d0c429",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:22da4ef0-566c-5d6e-96ad-87ed6ed40ea3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3a5555c2-c304-5e9f-a672-3b38c6f4bf5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4c0541b-5179-5b2c-bd30-180492553cd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51ef51ec-0c9a-5740-9ce5-797e7c7f2904",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ca388c6-8a3d-50cc-a744-bbb66bde9b1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6041462d-3b3a-5709-8d9b-00d5d11db919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a541b33-336c-530e-b2c4-7b645b4dce26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79826183-857b-5a7e-9a2b-a23ca02108da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:027bb4c5-b2e8-56a6-a341-1c3fc9e093b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd10d4b4-e66a-5d03-8553-7a482bbdc376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10a2220a-66d1-50b7-8b43-bd5e6338569b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99465504-4758-521a-84dc-d96057697c2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67d73154-3aca-5b6d-b9da-8f0bd95fc344",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6da817f9-0d66-55d2-ad70-975fbb1ffd9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:533feca0-ffdc-5267-a2f0-cb8330f9d5a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:42221365-3b42-51e5-81bc-f163e6615fc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea4e892b-903e-5bc4-82ab-ed2224205952",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ee26d43-fa1a-59a7-b918-d453c1d1fdbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba7e37dd-9ee4-597c-bf85-5a68fb31e74a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d07e72ef-5911-536f-83b6-85a148445170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69fea5c5-dc07-56c2-9970-6e70b0fc2b59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:61e8c611-733e-5637-8adb-64a4119c1833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:883cdc9a-6b71-5fb1-be1e-0b8434ff7468",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dfbaca72-bfcf-5f11-b9f0-336b2bc27da6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.2.9.RELEASE-tuxcare.1"
    }
  ]
}