{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:77fdb3e3-98a7-5faa-a664-e7269c42076e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "4.2.9.RELEASE-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:59330084-60f1-5cb1-a117-af2e26e0cd0a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf3a27a-d757-5e25-97cd-ae5561efa29d",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fa63d0f-e479-5df6-86e4-f12a1287bb3e",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b88476-7e85-521d-95de-17604836c3a0",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9faa44e-3ff0-57a3-9532-93aa4080156b",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e2ed95-da72-5f33-b582-728b10977f65",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98bd4ef-cd1c-598f-9bc3-09c8d6ba53a0",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a7f3570-bea5-5fe8-9a9e-8dbd7bc12a2c",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39a9c805-72af-5cd1-9cfc-3ff66640bea7",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55edb562-fd2f-5035-9346-77e840578d05",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20100870-7819-5910-9557-11ea4123c380",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dac7d30-3d97-5b07-9d4c-a2125da7d06b",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:babb4b56-8526-56a6-a9fd-b4f38894936b",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cf982d-ad93-55c9-86ee-c99d53a2cb5c",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca71583-ca2b-55f2-836f-f17bb428e8d2",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaa88303-0659-5c8b-9e4f-3563da83b80b",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce580b8-6b01-52bb-8fc8-4ee117fee5d1",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d20ed2a5-1c22-55d4-a70e-02cfc29f31ab",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca92f237-3e41-5267-9605-0375a2a65936",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9de0f13-c106-55f3-8f32-3d478c4caa49",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535eb8f6-a738-54f7-9295-706e14f70aee",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1cf007b-e777-5240-af27-9f531895cc2b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:006dce3a-83bf-5b91-bb92-d9ba9ed94b69",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad219da-cf68-5b4a-b17f-35fa7e8cf54b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6323f155-a9d6-5e83-af59-c4db9b4f1b3d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecdb35b4-27b0-5ecb-ae86-10922eda915c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c2e25e-7861-5bf4-b1c7-5c55fb1554a7",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30684706-a395-53c4-a163-e2aaeeb75666",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b74d2910-c5a8-55b9-ba32-dc464ba15388",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ea3b87-f170-5d33-8b5e-446a6ff8c706",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4dc3b2-6ae4-5dab-bf38-22f2d34ed9d7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07bd9979-2fe4-52e1-b39c-9a77d289d801",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:504e476d-130e-545c-811e-017702d85957",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74cda33-4364-5a18-a844-19fb4afc5098",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68b0d371-9b7e-5718-9c2b-146d7e59abec",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4890e497-a7c3-51cc-976c-fc1b43fc4c12",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a66ef95-ad3b-5583-bb1c-0541408f3bd2",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ffa4968-8473-5afc-8795-ab56debfb32b",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a9cf153-32d0-5606-8177-dc263f6b222d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05138261-fef9-5abc-b086-9b948955cadb",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b4162dd-b044-5075-bdb6-d39f23f27238",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b5aaf5-3014-5447-a7fc-015adfe14bac",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec9d4633-9008-5c6e-b907-ab971df5340f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfdb2573-c248-5b45-83ab-5e5a72974c23",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:717f3091-5a1d-52a1-abf0-0845ab8e2e5d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5045d64-3620-5ae7-8d1b-fe4b37d4923b",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc6bb2b8-f1aa-521c-8eec-d01b6084aac5",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@4.2.9.RELEASE-tuxcare.8"
    }
  ]
}