{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d48dfd10-50e5-52aa-968e-c9bb8d9cc696",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-messaging",
      "purl": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6",
      "version": "5.2.0.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:159cdfac-cd92-51ad-870b-2918460096de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d6dc13fe-bf20-50be-ad4f-d5a83e591337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dea1db73-dafd-56c6-870e-d97287d59350",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ac8007f8-a0c2-50c7-81b3-dc8f971c646e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01fb0899-f22c-582e-a1b0-162b203af157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f29426bf-3045-5ef2-a3a4-5d706bfa81c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:daa9a8f8-9e09-5e9e-92f1-49232420452c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85657333-8f05-5987-8531-e6a13b7b74e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5c8cb986-9368-52ed-b1b5-8e4f2051d74c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4bf2d102-b727-54d5-a55d-0fe9f8e745a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:900f11b6-2a08-576e-90db-c3de4ded868a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:102d9546-3609-5d16-968f-ee1fe66fb0a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bc8890b6-7b07-5e8e-93df-38d0036ab792",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9db480ce-f8ee-5805-9e84-55017b797d31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1211c796-e5ac-55cc-a0b9-d14745039003",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c0810663-c881-575d-a36f-17ecff0a88b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f72b4ce0-a550-5222-8460-7e31afd92e3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:760d86ab-64fa-5d25-aed1-a4427293e566",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:26807f01-7962-5a53-91de-0d661d7c4a48",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-messaging 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b7bb1ea9-06a5-528a-bb50-69e35643f864",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bc8370db-46b8-5dfe-9800-7af58ba14847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:26e63412-a7b4-56b5-a5f8-98e86876336f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c1f48fa3-8076-5cc6-a586-fe014846e036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f9065785-03ff-58f5-a45b-05bdf2dd1ca1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:17ce82c6-736d-5981-80d9-f8922a43dec4",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-messaging 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5956e44d-4258-5512-bf03-45df1d9887e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f4ba8f6e-4de8-514c-b963-36a29fc1dd79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:28b0827b-7576-59c9-a27d-f98ddcd024c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ff9ead00-f588-5086-a64c-e0ca1cb4c75e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7dbabe64-6146-556a-aabc-cc9058689686",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9d96417d-bd88-5b90-9f60-c4493d00c695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:da5a93f0-27fd-51c5-8e15-60aa96a18d42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:05467fd5-7ff1-5155-b0c5-fee7119bb241",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:36341c5a-ab9a-5842-84b1-1d718334fd74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e0127c13-1900-5fdc-bd0e-1af2a54095ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5970a1fd-db92-5318-b5b5-d4cd7c601732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f6c8b7e-4761-50fe-9658-72dd26cfcf0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0da120bf-170d-51d6-80e8-46c4fbf56935",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:09d8b0c4-cdbb-5c64-8c94-9cd85f1ddaa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:afba7a85-1c30-50bc-a2de-dc2e9b769bce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fc4e3c51-c6db-52b4-aa7b-5855633d72c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:926f53ec-a668-5494-a43d-44c188cf54ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f81a704d-d02c-5d81-b60c-1c51782c6878",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:078309a9-4e00-5cdc-a4f1-5a3bb7fc814b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3fb17b4c-d4d9-526f-9a06-d11e35838659",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:043c6977-dc60-5f71-be32-633f4f3f42b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ba49b539-4a8b-53f2-85bc-605ce6aa84d0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85d430f1-0f12-5b2d-838d-8e9bdbdd5330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:97d1febc-d6a9-51bc-b107-dd06163e9359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d67ae7a9-fedf-5b2c-9724-b6fa87738ce9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e6cc09f7-20f8-527f-a27a-cd939cb6b735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:93b08488-c24e-58f6-9589-cf798fe58a23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85f669f1-1c8a-50ab-a963-8a2062ee7580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c8f76199-5695-5c06-9922-4e97adec8a71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4a053ecc-7e5b-53bb-8f13-121da90b539e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8ef33e85-b9ed-51eb-85f7-cf5eb5ba967c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e34c5335-8a2c-51d5-a5a3-93b7bd116500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:457a1f66-619c-5c09-9a97-98f08f1b2f1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:680f5a90-cba0-57eb-8d15-c1f2f90d8c91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0f3f07fd-da51-5b73-b17b-9ed62c285170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-messaging."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-messaging@5.2.0.RELEASE-tuxcare.6"
    }
  ]
}