{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ead97115-e1b9-526b-9e37-855494f58ca3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1",
      "version": "5.2.9.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a3ceeee4-9f7e-5203-973c-49329668d202",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37205b6d-393d-51c7-9f8f-d3d233b21747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5c1d58c-e266-50f7-93d0-a89b359167cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b6d25bc1-73e6-5ba2-9111-bd93c7169817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4af8e1d1-26c1-530e-a820-93ae0f61cecd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f06fcdad-af15-5008-aa02-4b53f04328a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2294e3df-cd7a-57cd-b60a-bd959fe83f62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c0abf2d-7467-5cad-92dd-3f912a4bfd1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5fa05e79-743f-5222-ab5b-ead4d3eec151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:582c39fd-d6cd-5c42-aa61-55d4543d4ae8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69d6720f-d61a-504e-8c54-ee6ec50213a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7697be6d-3acb-521b-80b6-25060145fc9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d86c7cf-d170-5555-ac8b-47b8fa489fe1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d6b389f1-3477-5f37-8963-a9a407648bd2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ebdf95e-a1d2-5f80-99f9-0948cb9ce420",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ce00f59e-2e57-5000-ac91-3bec1cc792ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c0b6861-4ff3-558d-b751-677df7eaff5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d96e2d07-9c61-5dcc-89bf-7ea7401a2740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c52ed29d-e3f8-5272-b80c-c05599357ffc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework 5.2.9.RELEASE is not affected by CVE-2024-38820 because it lacks the vulnerable code pattern. CVE-2024-38820 fixes a locale-dependent case conversion bug in DataBinder's disallowedFields validation that was introduced by CVE-2022-22968. Version 5.2.9.RELEASE never received the CVE-2022-22968 fix, so it still uses case-SENSITIVE field matching (no toLowerCase calls) in DataBinde...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f029644d-b228-5cfa-89c8-b8b5103bee8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65e88919-ec42-5d07-87c0-82b1c9a2ee82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:302a4687-49a3-5e5b-8b17-6561313d4415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5a569dc-c2ce-51ee-b8cc-64aced11fc02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9661b6a0-9978-506c-9d8c-da8ff4c6ef26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a083887e-fa37-5ff0-a803-7c057ba71d2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:11666b07-9694-512a-ac2c-d25c2bb64299",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed1cda28-2d96-56d7-acce-f0e8d2e3c646",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d74fa9d0-6edf-55e9-b71a-f4f6affe3458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3e37497-adaa-54c2-b208-da8a98073c5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e083b9cb-d9be-5354-b434-40cce72d572b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fff40e0a-f4c6-538f-8875-1d289e21467d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5414354-6ba9-508c-89cb-5828e2dcb801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be643889-244c-59f3-89ed-cc45d45afbbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a99d551c-7696-5664-9d8b-071512c049e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ff12158-8435-5492-9a1d-e0e1ccb886be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2fd4b59-a38a-5f45-bf2f-89e4e6bb87d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1cb2b97-4125-5bef-9dcb-b44b5019f50f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c279093-c453-5368-9c6b-adbe7e53015e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b53962c-8a48-5de1-8cf9-db413ad9a24f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7caf9ab7-3f56-5642-b22b-278142ab9de0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73a865c8-b8cb-51b3-8e72-a631bd49a67a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44136595-a98b-5b8c-8484-1b4a8b823d49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf545c98-97c0-5d0f-9182-77188ef0a52d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18446962-77f8-509e-83b2-ee749cd997bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39e11d66-4b60-5e90-a3f4-85e636799de8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:385df3c3-8887-5079-bd18-c29892122bb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f996e87c-1c29-57d2-bac3-37e0e7c226b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b3507c7-24f2-5e20-8788-d95785e8e5a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:918d850c-4ad7-538f-bf8f-553fa481a4e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a916151-fcd9-5293-9ae2-321404e0267c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:995958d2-886d-5c4d-8cff-472896c1e800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:327efdd2-8f9b-589c-9f8d-3455d33653cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7bcc7afc-69be-576d-a4d2-3a65a8a631f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:282469e7-c45c-5452-aaa4-4206cb033703",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56b9a9ae-3a02-5c75-97f4-a3df027cdccc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2ccdd40-ddd0-59fd-bdfc-40a587f52769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99b0ed1a-4c70-5fef-a801-b141a19b472c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6bf5e981-fcb7-5fa8-9b7d-c2c199b756e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.9.RELEASE-tuxcare.1 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.9.RELEASE-tuxcare.1"
    }
  ]
}