{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:86966380-ed7b-56af-bb37-11014cf1ecfa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1",
      "version": "5.2.15.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b5cce4c1-534a-56ed-8e4b-080f87714650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f5186aea-719f-5f92-b862-3b3024fdc5c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6208d305-796d-577e-9280-d5fc7873eeb4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80c51890-1e1e-5ae7-986d-e84c2b9f5e0e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm. Spring Framework 5.2.15.RELEASE contains the upstream vendor fix for CVE-2021-22118. The vulnerable pattern (predictable temporary directory paths) is not present because the code uses Files.createTempDirectory() to create random, unpredictable directory names. The fix was authored by upstream Spring Framework (apoutsma@pivotal.io) and is part of the v5.2.15.RELEASE tag. Note: DefaultPartHttpMessageReader does not exist in 5.2.x series (introduced in 5.3.0), so only SynchronossPartHttpMessageReader required fixing in this version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6d7ec0f-e9a2-5363-a933-ebca29bd6519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c020de31-3d8b-5285-af33-d96db2fc21d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ddca6b64-9ab7-5e26-b3f7-2a4555a1a5b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b270456b-5ec4-5013-b9b5-fa802937c388",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4ed50ff-8296-5078-94a6-f63dfa9ab588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39f803db-8e44-512f-b213-093dc45ac4ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a073d3d8-4ba4-5599-a3b2-fb5a2646c8e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e5a5195-366f-59ee-9a85-8b49becf42e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3079eb46-9d34-5a95-9762-0a5dbe68f120",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e4e2327-8116-5412-92e8-fa082ed3b938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:224449e7-27de-5062-b1d9-5be8effce7d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54a1d1ca-9552-59d2-958a-efeaa056d0aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d2a4424-6c01-5a5c-8d12-5de2f4c94032",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a5a4b32-cf11-53e7-8ca5-513147f1ea6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc333360-595f-58c4-b729-4cf84d257e1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2ec0c49-dae4-5158-b6ff-80a26cc0330e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87a1860d-4bba-5b2d-9e0f-096f5a984cd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f1a7a1eb-8e88-580b-86b6-fd1e4adaea30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5566904d-73b4-5361-9d5b-3da7f8e1d2d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e7947cf-560f-5e44-8ba9-84932ff73ac5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0db1fdd2-6c28-50dd-941a-6a1806d97fb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:95945793-a574-578b-a2a5-ca4af4bbbc4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ff8d25de-2b66-5d33-b353-358715d35e71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99170959-a590-534c-a042-a9b2a56b83ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e033350e-0b1b-5257-9c67-4e8f389210ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a8c8e2b-5364-5c0e-9536-b8537182936d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7754bf32-dc4a-517a-87f0-65fb4e2d7c0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba398fc5-9989-58d2-9d8b-b2a58231e443",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:88ce30ee-9518-51f5-b91c-a2665b4a1b4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb62530b-3850-5340-9d48-34ed08c811cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46e7e8cb-0fc3-52f6-909e-b02a14e835ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c69cfda7-ab6a-5251-a379-633c8dab1afe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f553ab93-b41a-5f09-9b6b-00828a511db6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4dc1d211-ec20-508d-b9a5-ec6417c64c0f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 The target Spring Framework 5.2.15.RELEASE is not affected by CVE-2026-41847 because the upstream vendor (Spring Framework) had already applied the fix in this version before TuxCare onboarded it. The vulnerability pattern (filter lambda capturing outer scope's serverRequest instead of accepting it as a parameter) is not present in the codebase. Fix commit 3ab270e0f1 by shindong.lee@riiid.co wa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:77c08727-7b2e-5ce1-a3c7-06328b602b54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c788036c-cc03-543b-bdef-667ba0f3abee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55ce70bc-e505-563e-a027-5f343d5930fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:108cad3e-a367-5a84-878b-14eb98805077",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ee4adcf-8de5-50fa-8aae-1baeaa2ebb99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0524c9e5-845d-5292-9476-e8da492f252a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12f29dc9-a129-5da1-ba80-5dbf72a95217",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67ff6f28-1021-5f97-b55b-c3a084207ae9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a319e33d-52df-54c7-b5eb-8129d3398223",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d0b9113a-a459-5b81-ac0c-cc2959eadd18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f81a8346-267d-5fac-92be-d1b422f84262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e029344-8af6-5bb9-a7ad-55111b74efa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0dd52927-07cc-561e-bc6f-b22728a364be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:092aedae-b655-5820-bcb7-357c2cf0ecd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b60a09e1-0600-5722-b486-c7418e398b2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c88c77e7-ddeb-5440-ba6d-cd2041a5d6ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:04956e50-ee15-5dae-b426-55dd9470175c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:450d6c4d-3d03-5e4f-8e27-9ad05e1687af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b52400a1-bb9a-5e29-bc71-c20aa6c509cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1166239b-137d-553b-8a4f-982c3e971938",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.15.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.2.15.RELEASE-tuxcare.1"
    }
  ]
}