{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9e4b5ffc-2071-569b-ade4-d76bb9007e0a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-orm",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2",
      "version": "5.3.33-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca6a2b50-a717-53f7-84a6-3ad395f4e38f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ee19ffb-c3ea-5d1e-a7be-aaeb88bcc999",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d4b25eb-2aed-5686-b38b-118e061ba3e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6b6bf325-f586-5897-82a7-6ca2c5c12787",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:970ee8c6-26ad-52d0-acac-a2194556aaf1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aa13bc3d-8a93-52c9-b760-eaf695c58a12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ad0f8298-f3cc-5bdf-bc4f-40f4dae6c748",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c4009a1d-2981-5167-9ad3-fdafabe282d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e9bca28-0123-5b8c-8a00-3550b4abe9e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0042c43-b506-58b4-b116-bd673a408514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:690e6a05-4e4b-514c-b788-8f63928b0efb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b22c14ac-4940-5ad3-84ee-f1f07226f39b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32773512-1a4a-526a-9602-cd778afafaa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5513dd67-4c10-5366-8766-a30767adf932",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b19da57b-38fe-5f5d-96b5-af0adb2de7f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5d1f5f1-10d0-5286-8d3e-64aa957d631d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e0180f92-c6bd-5aa0-abbe-15eb7b99c66a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:860b5105-ec82-55e1-bbac-04c25d45b51c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:69be3332-d4f3-56a5-ad66-4bb84445d78d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:27839c35-5f47-5ee4-9d33-a42580cf6434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4a425c0a-697a-599e-b9ca-18305ac28479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f35b491-0564-5d50-bf6d-a4c9b421d7fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2c5fb6a2-3071-5635-9a11-227ae3678d73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67f75ea0-3041-5c31-b7eb-6bd0d76d978e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bedb3f0-c586-5221-871b-082d25171524",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:90a80553-9d37-5e77-9882-a73eb4c77c06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a8556de6-57e7-59d5-a7ca-0ae92c6667c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd665b2a-5e6a-5fb0-9626-cf11c23bdd17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1965766a-31c0-5d86-a078-56bf45de7767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:266a249b-3cd7-5c37-bbbd-991138008962",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6ecbaa74-040c-5fea-a821-0f40a3db58f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:10cd9a5d-6b6b-5dd8-9094-d516d14f0586",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:39d5326a-218f-59f7-a7bd-b37a3f47b1e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:08dc894a-ea3f-5547-9492-4a2864bde902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d3afbced-0f42-50d7-b22d-884a4f5a5859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9b3b515e-ea45-56ae-a365-0a7ddcc1a82e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7622c1b6-ee66-57dc-bbd7-b136a757a32d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9259565e-2b2f-585e-8955-2dba2faf940d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e5fd8e62-67de-5746-a59f-b5b366ca48fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ac3a805-ae67-5a10-aa4d-aa85c926ce45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9790188b-e3fb-5026-bdeb-f460cbde8dc6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:56cb5831-dd48-5e06-b1a4-5c98826fedbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b38cdbd7-2f72-595e-b4d0-c04e513dd2b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6d2068ab-d520-5baf-bae5-3c89d2df8747",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c99dcdad-31cb-5d63-b438-0129c370734b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e601dcb-776c-5bfb-a561-d28a1ebe668a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:59de46b6-dbcb-5cde-9bb1-34dd4755dd4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4241869e-1e15-5b29-a618-b0e1b344442e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-orm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.33-tuxcare.2"
    }
  ]
}