{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:380ffa1f-dcce-52c5-8b86-68f0eb832123",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15",
      "version": "5.3.31-tuxcare.15",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:0de210fa-f04b-53ec-b98e-71c82c112f6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ff20b164-2e62-5467-9fed-0fb552db3d0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:6d1b3823-3aac-5898-a8de-04796c2501cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:155f911f-4b42-5f49-b588-ef5ad3024419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:85562650-a98f-5abd-9561-21478f27358a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:d03183b7-68ea-51e6-9956-fd04428f119a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:b5d667be-386b-519d-8dc7-7eaabe4b7696",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:f289d6a5-50d0-5013-a78d-ffab98e36139",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:20397fcf-82fc-52fb-a48e-e71dc88265f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:6b72b741-5593-5975-bc77-d5a79eec9a7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:03bd2aaa-9d1c-56a9-b46f-af71df77a6ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c3157656-9075-512e-a2b1-9cf599614e7a",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.31-tuxcare.15."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:dbce7225-0abd-55c1-8e21-139be0b150df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:4b3432d5-ca1c-5d26-a68c-ecff7450eb4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:0441260b-76db-59d3-bb94-041272a5bdd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e70b9399-8193-57cf-ac6c-95c349c62eba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:1a86bbe5-807f-52a1-8477-37777983a5de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:2f7cae40-556f-527f-babc-f2eb7a72ff99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:275322e9-9032-59c5-bb90-3507782d1909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:854149d9-7cbe-5b09-a8bf-bff82e0c1644",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:0bbce71a-6dad-50dd-89ac-f78d73ae0ca4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:cf942637-17ce-50a8-b77c-4ce0a5a6a143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:0458ae8e-7a86-5084-92fd-d8cbec1b32ac",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:02f7387b-d023-5d77-a2b9-b36e25414b8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:9da87dcc-cba1-5c21-a812-d6198ae86918",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:a773ad8b-a039-5945-9b3b-1c6da9da51da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:52f30540-fcdd-5313-9521-3429de97b1da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:3036fead-ac9e-554a-a96a-4888ba72d02a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ede4b07a-4036-5598-ac65-04d2122ad3a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:96692138-47f6-5223-9a19-46c26e4228a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:bc9ca54f-dff9-515e-b27a-f32d21893027",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:710f395e-b621-58a4-96ee-987aa478f430",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:7fc330b8-f754-5bf7-a129-59483ea182b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:80e6bf1b-e83b-5a14-bb7f-9f98d47f3e10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:0918a6af-c0fe-5df5-8891-52fad158a230",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:70b832ad-a33a-559a-a445-037a937bf4bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:1703c858-874d-5f5c-840a-a65bde85c730",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:79684727-1f7b-58ad-81eb-2dbb50b49522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:1068c111-b44c-5286-84e8-d8190a945196",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:266cb275-ec3e-59f3-a8f4-9afae08461b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:4b9873a6-ad79-5c0c-b21c-f7d7b6a4062c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:36ea8a66-7dcf-5e70-ab1c-dc1104a5d266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:42d6b82c-0a4b-5000-b66f-1c9660f17256",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:8ebafe2b-b980-5d44-b5f5-145280fa3400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:4a0937f5-8641-5300-b3c5-7656c6b6bede",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:4f3b72d9-6962-5db4-8ef6-a19abaa83035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:654340df-0020-58eb-beb2-a4784114cad7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e7491e1e-2bc0-5d00-9a1c-1bc0c85a5363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:08d921dd-8b75-57df-8977-bfb7053761b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ce4b919a-8059-5191-a2b4-cb9f2b6befa9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:d88ffa59-f343-58b4-b336-0465d2d1d85b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.15"
    }
  ]
}