{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:28b17d26-2bf4-5304-8076-4f31f13d1afd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-tx",
      "purl": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1",
      "version": "5.2.8.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67ac0422-eb81-55a2-a9df-f73ac829da6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4516b944-13e7-5d87-b724-65063768a965",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5515be69-0bc5-5208-85db-a469cc673388",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e7cf435-9778-59e8-9359-481707f7b322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1973c603-fc0b-543b-8d12-b67b8445eedf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:77d4f97b-7ca5-5e06-8775-98cfe06c62c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4768f99-5b54-57c9-a333-00a030b36d60",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9bc93769-8a52-5a66-9701-cb6df35c5a91",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:03fa595a-fc8d-5381-a374-98e00fff3d17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e095b00d-4b74-56c8-9dfa-c91906a7c5fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49b5c60c-d31d-514c-bf24-5be6e480d9be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0372b9cd-9218-5405-800e-c8461a667d71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e5c5488-f593-5215-b324-5ef789e2c46f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:353cb2cf-a8f9-5736-83d0-9d38b2c1b4e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b82319c6-6244-5a9f-9196-4a0b0000a14d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:315a55e9-9202-569f-8db7-5d41b0d969f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38ee578a-9857-5b6b-9681-d3367954b4a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:255bd7cf-5edc-5a40-b327-980a7e94a235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0a7904c-42d4-5d1c-9c25-c07d66b547db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8d2518a-ccb6-5a0b-bf36-382298fd647d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 5.2.8.RELEASE is not affected by CVE-2024-38820. The vulnerability requires locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, a code pattern introduced by the CVE-2022-22968 fix in later versions (5.2.13+, 5.3.x+). Version 5.2.8.RELEASE (July 2020) predates that fix and uses case-sensitive direct matching without any toLowerCase() calls. The vulner...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f76886ed-de9c-560c-aa1c-bcac455a225a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5fc72414-e510-5433-95e8-027bdfa3b0cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:41384eae-0bb8-5d13-ba32-bc1987726e11",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx. not_affected \u2014 Version 5.2.8.RELEASE is not affected by CVE-2025-41234. The vulnerable code pattern (PRINTABLE BitSet without double-quote encoding) was introduced in version 6.0+ on Feb 1, 2023, approximately 2.5 years after 5.2.8.RELEASE was released (July 21, 2020). In 5.2.8, when using non-ASCII charsets, only the filename* parameter is output, and double-quotes are automatically percent-encoded because t...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9c437e9d-5e50-562e-aa89-119ae0e7fec1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:460ba93d-2104-5801-8566-fe6a68b9ffe8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5457a28-04a4-53da-85ef-5f085a03f469",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d16000f-cb14-55d5-b7a5-db63a7b0304d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:11a5fe9c-df31-59d7-9117-8b6979409f2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef9c4642-2a2f-549c-9496-2ab802a04d3e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1b06c25-db37-5bef-a805-aaeb42d4371c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7081dcf2-8f73-5b0c-ac0c-91aebcc1e251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3acaec5b-886f-57b0-8307-a92fdcad855a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bb8f50ad-f840-5b62-be71-e5d00b5345be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b6609d6-2c19-59cb-a38c-7d6c875a4c63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab820475-3a0c-536c-b649-5b8a3ab2ad87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eab005bc-d2f6-5947-94fe-86c509b81f3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3e300b2-9c5f-5a6e-bf15-57f0b5079075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39a89857-43d5-5444-abaf-2de1583a3c7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:861a73c4-de46-5143-b30b-91862fe06850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1c64fd2c-1ec7-576d-8c1a-a1ccfddc4bff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30054721-2f77-5e98-805e-64f5ccccdb70",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1a15615-a605-557b-b02c-0feab7e64999",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8154f400-4afa-5e87-acf1-416e7f9b73f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6c49f641-82ff-5b28-be4c-62948d096ba1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa8f0f68-c9dd-560c-b221-5ad9674b2fae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6a87876a-8217-59ef-b0d0-1a3a9bffa1a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae0a066e-3415-5dc3-9be1-b1a84db4d04e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c451f9d7-8fb9-5778-95f2-20aa0bb69ba3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2cfb828-daf7-5066-ad7d-7e4b10cbb70b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6dab8ff5-6c2d-51cc-83b3-d5a90206e3b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57ce785e-827c-56c7-8c7e-42c1d9ba2f18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3ccba2b-d088-53f8-9330-43cb6f853f3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71153fe5-6d00-57bd-890c-4df3e5ff4acf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6caa7074-2be2-5db3-903f-c897ab125bd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:797c845d-8606-516d-9fbc-5c54d462240e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72dc7039-a067-5c68-826b-928ddcf61baf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a36b60e-9b8f-5d07-b78c-39734615668d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd58a546-892a-5dcd-b7fb-55ddecb63620",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:005f6b5e-8aac-5800-9f1b-139a9ea30894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59774579-052f-5c2d-ac8d-5a1ca2ffe722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b386bc34-1d21-5c65-9c47-76c69b43b445",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-tx."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@5.2.8.RELEASE-tuxcare.1"
    }
  ]
}