{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ec7b127c-903d-5e26-868a-92edceb96221",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1",
      "version": "5.3.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c751959a-e12a-5d2e-8152-a9b54d2584a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:179a6409-f996-5d30-b28b-2c60d420d6a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb2f1402-ad16-5436-a887-7094c626837c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0969a8d8-7b18-569e-8fc0-f4c2ae0c5815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8770f2d3-052c-5efe-9ce4-a1ad407fe47e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:457c2a86-f49e-5722-8b93-770b46d7675b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a3841a4-f42a-5e07-8e59-87ba9da2927d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d147f94-6f20-55c9-8f3d-5d10159a3741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:afa5d1b9-400c-5256-b21d-9339642c9559",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40b19a92-0d7e-5c1c-98c5-bbfe5d22c9cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d74f328-d42c-57bf-b223-f18a9c58fbf3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53682dc1-a193-5d04-be79-58e3c28a5db5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3de736d5-286b-5e31-9dd2-15499f251174",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:393a2fbd-89d9-5f5b-b8c7-2fe2f754a177",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8be8b0a5-385d-5354-81eb-d3ca3c3384e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9810bc5e-e598-58bc-a340-ba9251de2942",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82a72337-17cd-5020-b75c-55bf4f05d7e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9685b46d-5590-585c-afaa-656d5019a023",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:023bd54a-9ba2-5c32-a0c1-556ed312c54e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc6a822b-7e6a-56fd-8713-790f62052e0c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.3-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 Version 5.3.3 is not affected by CVE-2024-38820. The vulnerability addresses locale-dependent toLowerCase() in DataBinder's disallowedFields validation (introduced by CVE-2022-22968 fix). Version 5.3.3 predates CVE-2022-22968 and uses case-sensitive field matching without any toLowerCase() operations in DataBinder. The vulnerable code pattern (locale-dependent case conversion in security-critic...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73a1ee50-cd9a-52d2-b0b6-ddc3c7cfeaa7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a45dc87f-0289-5f59-841d-f76e8063238c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:03b34e70-eccf-5651-98e1-763f9b66eabf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99486f0e-a3c2-50e5-ad48-9f8f78f64b86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32f1d568-f39c-5494-8cb3-bb4179eb63ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89b6ef3b-07a5-555f-8199-a944c6172b19",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d6fabd1-64f4-5bfa-ac31-516fceefe46a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1f1e24db-b3dc-5687-9663-849ae1d0429e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cfd70ae5-319d-5439-934b-4846a60f31ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab887444-bbdf-5485-8296-ae836a1dcd47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:201029e7-bf8d-59ae-a239-307c8be773cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed1b9d87-9b9d-5e4c-a6e4-dfb4f8f02d05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0be227c1-cd00-56e3-83a7-388482d1838e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a34da69-3734-5299-801f-cb6fb9597bd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d7d7297b-ee9e-5064-b119-168292682014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e542e127-bfef-5605-af9d-b5a898edefe1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b3274d18-0089-5f33-a980-105c1728945b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd93e5ca-7cb1-54a5-875d-a1c9d931006f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b0b59fb-61a3-5d7a-80ee-1e5bdb3756d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5a06b58-8a6f-5052-b286-f01a787b021e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fa952b6a-ccc0-5fe8-bebc-3667f1543e6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6118098d-8ad6-5047-a7bd-8c2daba28e89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e48da40-0266-5419-adc7-a426078ad3c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0087568d-0b50-5f7f-920c-939217409844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6206dbf7-3c62-5faa-a672-6b0ce9132c31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3630b3c4-cc25-564b-8c80-7234612e3bbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76f88d1e-7995-5308-8314-9863b5c5030e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64faf057-4f1a-5774-84f3-d54c659828a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94182350-77d7-5346-a0a8-1e1c6acd30ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc3a3fbc-5b2b-533e-ab1e-03c0d6ec9486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66716fdc-8b2b-5759-877c-7e624fe4bc47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4326ffa6-7804-52d7-b013-629d7dfc5909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78dd0204-fd81-57ae-973f-59caac57ec5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5346dd54-8a55-5419-a7f4-15a91b680268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49b3498f-9cca-592f-b45e-a8bf128696da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8bd6b91e-5c23-508a-b414-6031bbe8a1b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d115a96-1efe-515e-a76e-994e37161180",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:117b5d07-e0b8-5a82-aa41-e0dceccef574",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9c1c9522-b1b4-53b8-b249-0a24e3bca251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:58fadb65-666a-5f35-b1bc-400e29596347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02fff49c-d59d-5db3-b18f-1a80667671f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.3-tuxcare.1"
    }
  ]
}