{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:80f7c392-219d-576b-bb36-a2cf14749968",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2",
      "version": "5.2.11.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e709c45d-315e-5b11-a074-8d709ce7adf1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:297ac944-323b-5025-8472-a5cdc36e7843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ed426de5-ddd4-5cdc-9bb1-5733429acbcb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:661b9315-ab1f-5be1-aaf2-26ab65ec86b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1367c44e-fe7d-5d86-954a-b2455b7056d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e70d168-6264-5795-a459-53ab938fab1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:437105d0-5cc5-5c2c-a749-ade4a37e73b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e99096a-fc05-58b7-afc2-191f40dd0a8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b246354d-9c0d-523a-866f-84aa2c5667ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca2b1b16-a812-5132-b974-6e3e5a04564b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fada6efe-0a62-5615-937f-a25e0ba07096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8ace8571-8aaa-5551-9818-dda1e1dcf252",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7fe2688a-4be9-5052-a0e0-03f95d7bebc2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0fde8930-002a-5632-b3b1-aacac2bc81dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:731a2815-5160-5c4c-8bdd-7f8326989bdf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9fed0994-c4b8-5e53-b425-e65bf8a458dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8283c796-ee64-528e-ad40-f0a8d9951853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d5fbdba0-f190-530c-92c5-073a63f42b8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:407dcd05-44bb-50d5-8fb5-7630b74c60d6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0873b398-223e-59fd-b112-e9e70299d7f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e470eaa3-fcf3-54bb-910c-ed10cd9d7701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ac72e27-e1b8-53e9-a3fd-b3bade15c029",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a6abc251-dea6-5330-b5a5-dd333690843b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d9da0608-f289-5842-b4bc-5d70fa067833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7085e94f-d159-54aa-8e43-87b83cfa2cc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:56eb4f6b-cc02-50ce-98ef-39de2f21ed5e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de755a62-b15f-547f-9a3a-762d26eb9aa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c036b5bf-2b2c-583b-b407-c3aa5ffbe924",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de06524b-608a-5200-a03d-c49fb0676f30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f29f53f3-f153-5b33-8837-bdaa587b87e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9845459f-c0e5-559a-bdbf-9d5883e3078e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:315b97b9-d49a-554f-9154-d6f1f3e12ab3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cdf7655d-d4db-5521-9ba6-ce3b95b222ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:435eba9d-1123-55ba-ad1a-6f64579deb70",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8519f9be-bdde-5628-a43e-7bfe118d0071",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00be8a40-9fe9-5a49-be28-b719140bc9c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0bc56da1-0c19-5eca-b986-b58ab610bfea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4b74a942-ea0f-582e-9a02-a7f46a429403",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:390e4146-1a0c-512d-badd-71924dc961f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2664d210-2fb0-50e5-84f2-b80429d14a15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a4cdd29b-b7d8-5467-be11-97f2578e4bcd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6ad3ab51-1a93-5672-98a5-f03c221835f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:59e90b70-8df0-5fef-b0d4-32809d503f9b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:587780e1-6e9a-58bd-b099-b03ad5572d6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97f501e1-b6d0-5628-a2cf-5d85f40d65d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:37eeff89-8653-5d14-a6d4-fae8cd69264c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:080dc5bf-031f-536f-9445-80640ba06bda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d981db3f-2212-5d19-9b69-e19d7d16cff0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7e7eed67-23ad-55db-9056-2ecdf5875b11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6fb8f5cc-ca9d-56f4-9244-af7643122968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2543c87e-03ed-5754-9a03-2e8d9b258633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6aaebf2a-221e-5b14-8674-b1966bbffb5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:71404dfd-6b4e-5cf6-82c8-4d3a14bdaf43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de11207b-0823-57db-8748-038784c8a517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ad5d4095-17c1-56d5-b21d-1e76eadc2794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0592c697-c9cc-598d-951c-5af59559991d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d9c41820-e947-571e-9b8d-9e7b8d6287f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:761459d8-e798-59c4-9be1-6c99f60cba9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.2.11.RELEASE-tuxcare.2"
    }
  ]
}