{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b3d0e33a-a0fe-55d3-9526-d0e4e3eb1785",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2",
      "version": "5.2.7.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:566eb712-0e90-56d4-9473-7641818bd126",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fae19393-9e31-5bdb-82f9-6f01591abf5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3855a726-1801-5463-823a-94471561d863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b45b3104-5443-5741-a57d-bb5457c946cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:81a40465-f482-5cc6-b2aa-109c797cc397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c59b9ac3-f155-5320-a839-e23b2a8c3709",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2d09df02-bc25-5957-b825-8cf9021cb900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f8e417e2-f981-5bad-a325-d7fe1f3f0a39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9858dd97-ca26-5948-a873-c565e199160c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b930afca-763b-522d-915f-f0752460eb14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43256f80-9147-5abe-920c-5668824d8d95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1dd6c7b3-98b8-5b2b-9308-f2fa5d26fbec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:24c04cf8-325b-5518-97bf-d1434283851a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e379f670-e3b7-564e-9dc5-71c3d90d5c5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d2946d8-3e56-580b-b562-02f24229779a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:63326b1d-4ef3-5211-804f-88d41c0f18c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a1f9787c-4925-594d-8ef1-fde8e7f5975e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eb475696-6b60-5f7d-8a02-bd5f13a7d3d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:25dacdee-134a-5b62-998d-ff5e9e0f8f09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:07de8195-5259-5670-8c37-f9cc433d5f24",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a19ce8ab-b23c-572d-8fae-2001f13a557f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54f562a4-e3ea-541b-aadf-490b68cc12e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:349739dc-0931-55f8-a1f9-2939bba20cde",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:770cc939-25f7-5874-b9fb-b7ef5431d874",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c8ec6b74-1162-55e2-8a38-91945841d94b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:caeaec8b-ae2a-5e0e-a867-4c0728bd749a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:47848602-1627-5495-9363-a65a629f6aec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:813d45e0-3105-58ed-ac1e-df749b6859dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e93db0b2-3ff7-56eb-bc14-11130c27d8e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:661679a6-9a3a-52da-9867-c30072c470e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5724dd1c-f389-5585-a84a-fb680252e0c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a3d3dfb4-1eb8-54fb-9310-b21c3b61f879",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1bfdfbdb-e130-52a4-b788-4a0eb7984757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7e273b65-ad20-500c-b2a1-7d938347df9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7e741cc5-f7a1-5204-989a-8b836d896ce4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d2ec241-4060-53a6-8dbf-4c8857376ce8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bc0ffa05-5f10-5dad-a1b1-7eaf0379ff4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9012efb2-4392-5c01-a039-fb6d00fdb987",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7d17f174-11fe-564c-b63c-96d7bf7e4b6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32afe513-9a01-590f-af17-1136a90ad53e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e86bb8f9-08f8-5ea0-bf6c-71ba0dc8a4e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:26c85040-46e3-5efe-aa92-45aa2a9dd05d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:380409f3-5809-5e23-a542-3f1d3b5da22a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9825a7fe-b039-5885-adfb-95e4931ca7a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a4fb830-a556-5071-86b7-ab6e22c4b5f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:320787c3-4de8-5ae4-a364-f0a084f2d350",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:407a6326-6d39-551e-90fa-9b698ad5172c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4e45027f-24bf-5b3b-b2cc-05726649664d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:36609011-edd1-5f72-be8e-ea8e60c7ef09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:24d85c92-e6b1-5a82-8a39-b878052ca882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:afa54712-681b-5833-bf10-7e7134e80138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:73d3df47-b636-5203-82bd-245bded352a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e075c075-be04-57af-85d2-3bce4fa6eefb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:07eaf6b1-46b9-5565-9c5a-77f3e2ede09e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a8149aaa-5676-516e-90e2-1d95f32b041b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a14a546-f7f0-5b18-89ac-294c4818e7eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:234e6a70-e967-55ff-a811-c40042252c2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5d1e66f8-07d9-5b42-a859-d486d5301441",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2334ba6a-6d17-5435-baf8-3f22ad944c5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.2.7.RELEASE-tuxcare.2"
    }
  ]
}