{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:46151ee7-05eb-5048-8db4-d3f6eec29484",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2",
      "version": "5.3.20-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9a007140-9126-552e-9ee1-3e06ca271a9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67f59a58-7b78-5e43-979f-da230ab522ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cc6582f5-7292-50bc-8514-37268b42ec9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:14b4795a-08ea-5e84-a3ef-0a6b6c073acc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8a545b84-099d-57c7-9b10-155cf1839173",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f791ec5-7fd0-5d47-9ff1-9ad40f0fb0ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b723e388-3564-581c-aa59-695a241296db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5fcd91af-9b7e-54c5-a478-7e1fbcb714ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cdabe430-33e9-54db-8ab6-f0d00d00d496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b439f52a-79e3-5a5d-ae84-f199cdc2330e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:71fa0e46-bb32-597b-bbf7-e7b9311191bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f138bc3b-88b5-5f63-81bf-870fec93ec6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:604a068b-a93a-5efe-9c32-9680e84b98cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a5f543cf-f53e-5527-aa53-44c31e5c9ef8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:043367e9-0505-5180-956e-844453996a3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:430b6151-1150-5a45-a59c-55fb432b1050",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:44f9eb86-092c-5e3c-a51e-77cd67d98317",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3bec67a4-7b02-5b86-b42b-2e6a5f2999ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d29f491-fc0e-5ca4-9610-853f802d5bae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:92505f80-b236-5b1b-87f1-fffb9138e102",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:326650b2-8331-5a21-a7dd-db5cd027b5e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a095696-7bb4-5281-9b6e-a87a13640c48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e217736c-deb9-596e-92ea-603916cf5ab2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:49f8c764-0b09-51b7-b3b4-84f98eb4f16d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:07d6f611-d288-57e8-a291-48835734530f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3abe0594-ccad-5d06-93f0-177c0be95dd1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d3d51259-6228-5165-b4f1-22f91032c6b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:870f0b93-70df-512a-8f2c-e397ec15927b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:15752c2a-27a5-531c-9851-c36f8e4c0cf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5982089e-82e3-58e3-a11e-b24124f1dc08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:032c0420-bfbb-5f83-852c-ce61a0b615ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:016eedc4-955f-51a3-9d80-af94b0d6e3f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c854cb3e-40d9-5353-9a3c-78bf4e47c7fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f88b90fb-4abf-56bc-b41c-a3d4d2906c10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2167f464-be60-5de6-abea-09c366b44527",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3fc9b0de-d752-5e1f-8040-26ae9645add0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bf65dbbf-3ba6-58a2-964f-0dcbb9e6158f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9637c4f7-b74e-5744-b201-457a148f39c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7bf874bd-af93-5d8e-95c2-4ef4e449cdf8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8ab176d4-bb15-52a9-aa4a-f5cfb69ce2a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7fa2188f-db71-5d08-8038-35fb5149489b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0d6b610d-624a-5553-beea-fc3b2725570f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98cfc350-0315-5d7f-9dd4-00d4424a516e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b848f7d-700f-5c8b-800a-cd52e8bcd62c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b6a94431-af83-5935-9169-c4e341e75d7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:efb6fcf1-776c-5ded-8234-a0f983165788",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:048d560c-05db-540b-95bf-4916e512da0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ea1338f-34e4-56cc-8947-794ef779a545",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cfd0efe3-1cb0-5ef6-9bb1-4de770c2b13d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c924198d-b20b-56b1-b40f-9b2288140e5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ef34e2ba-40b8-5c78-bda2-cdc4999bd673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fe2bd21c-048e-5cc2-8960-70f7c467d88a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2f6c506d-1428-5370-9382-e774506ce4d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.20-tuxcare.2"
    }
  ]
}