{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4bd32675-3959-5584-a00e-cbc18ee73776",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1",
      "version": "5.3.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52481148-5eef-573e-8d73-975373c56a01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:abf7a90e-7c7e-5259-9fe9-15ac0309f8f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3a6a3c9-c032-59e3-bfc3-d9454541a7c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:08f7c7a5-05b8-576d-b5e5-96e0be114670",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b9523232-a837-52cd-82fe-242ebdaac652",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9a48a2f-3752-512c-8ace-4e441e748b56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3c2ff1a0-8b7d-5a4f-815d-d37ae3c87032",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d78e27af-ff3f-5da4-b8b8-62e72dadac84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3189c27-cad4-5dea-8afb-49fadd06319c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:123c322b-a5bb-5782-bf4c-6b165ddd3157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f12c5e10-c201-579c-9f97-ce6212e887ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9aafc497-93c0-5cbb-b380-611bfd006fb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dbaca5a9-d95b-55bb-9eaf-8d1994a05a6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57834899-ded8-555e-bd64-a1127f374879",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ebb4685-6689-58b6-a876-7ba783b95b4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64339357-6bdc-5bd8-89a5-df99f638daec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49a69cf8-5024-592d-bc49-8ccab2330c95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d7d3121-65f7-5f97-baf6-c666e1257de2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b9c75b2-c957-5b17-bfe7-830d6cba4994",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81d1625f-7009-5bb6-bc58-3b38ef080537",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc. not_affected \u2014 Version 5.3.3 is not affected by CVE-2024-38820. The vulnerability addresses locale-dependent toLowerCase() in DataBinder's disallowedFields validation (introduced by CVE-2022-22968 fix). Version 5.3.3 predates CVE-2022-22968 and uses case-sensitive field matching without any toLowerCase() operations in DataBinder. The vulnerable code pattern (locale-dependent case conversion in security-critic...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b4c80861-c8b8-5ba6-9d82-fc83f8991b87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a7c23644-7c69-5ab5-8ed2-bae2ede280c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79abeb78-73e7-58cc-8543-95f53ab96e44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f09c74e-fd3b-5d91-b9ae-7f14cf62f220",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2c01447-47d9-5042-8f2c-7d817f64121b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7105df42-f277-570c-aa87-08a220d04321",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:576577bc-a7a9-5c9c-9fed-b62db882a297",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:259cf6bf-ad61-5e68-8ee5-e152f3820e34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7aaad082-01f0-517d-8296-36679b337ea9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3d037818-1f0f-5d63-8899-128bdf16624f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cbc3aa75-5923-56bf-a6b8-2d636ab3d6ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53437b30-aefa-57a9-ae8e-17d1c4b685d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b23a8de5-91a5-5463-9db7-69740253b01f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:907febdb-f851-5fb4-82a3-d7ed0998b9ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36f3fe42-0b35-5823-b6dd-a7565ff26992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc676127-1a57-5928-a2c6-a9bc82e0216b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b86d2efa-4d39-5288-80a4-fcabaed7cb6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f18ba4d-0553-505e-a90a-f593aad7847d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db523f29-ee7c-5893-866d-ec0f9ec4729e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89650999-3b36-58b7-8918-cd87e620ec9b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:875759cf-4298-545d-9d16-bbec31b3daa9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72e9c24a-e83c-5908-aef0-34dec2334a77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4d1c0c6-f543-50eb-9c43-e326c18aecbe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ae7658c-e48d-5e98-a745-b8e86f0af4ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:176cc528-ec7a-5e25-a9f0-3a620619ff22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:978e277d-6f0c-55e6-92df-a8e57807ccf0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc3d750e-80fb-5bf0-a097-de3ca8336e53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5508b878-fc57-5cf7-bf11-3387602e9f65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e31a1be-6311-52a4-b859-64b30f19a66a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66c342e1-1d99-5bab-ba0b-a5ddbc10e4e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71b26ce1-318b-53df-ba11-c895f276c232",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d696e257-b410-5dab-850f-525a1467ba9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71f2491d-86a1-58e7-b862-a1e94953bdd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b5287130-0d60-5a2a-b9fe-2e29f16318ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae857828-d000-5606-9792-5c9c30efb6f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3d3fe5a7-4019-5b30-aaae-ac95117f3795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3f11a89c-4359-5db1-9a7a-4d11de1bfad9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b67c5f01-8a93-5607-9458-0afdca0040ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c03cc1c7-074e-5676-8c7c-b944b3bc2651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7189234f-206e-5191-bb84-79a0fb5016dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef21bfb9-a99b-5cf5-b3b9-79f4e2e31fec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.3-tuxcare.1"
    }
  ]
}