{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:63341bbb-ce9e-5bca-a2ba-6d2905c3eb79",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "4.2.9.RELEASE-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6857240c-6431-5235-9bbe-3b91c5666bfb",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3baed49-321e-5093-ba89-3bd1f05028ea",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77293776-2c84-5c98-b394-517375611dfb",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3cdcc44-8e05-56e4-8a7d-8ad2d1708ca4",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e23670c-efaf-53d9-8432-92632932588a",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18366493-18e4-55cb-85c2-d5ad9ba92375",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3213c13-7a55-51f4-8931-3700e99ef786",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfaa93a4-9a93-5ceb-b559-1bd01efcb9ff",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e94451e-cac2-5112-9f82-ff0ea27104f8",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55fa53e6-2a8a-5417-91dc-91adc975645b",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64fbdf3c-a996-5049-a10c-1d3f380d1c3a",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60fc41a6-4899-5ce5-b58c-06dfbc1fe893",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f212d53-7646-550c-bfc4-6628b13f43d9",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f57bbe92-7b5b-5653-a476-278dfb36e9f6",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d518d7b-d10a-5608-bdce-7ac3e3302162",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543e729a-e8ab-5967-952c-f60aed315793",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d493db4-c6fb-5a92-874b-2811de55b6ad",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea5e9173-5ed4-554e-95e0-7c6c82105e26",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b974b4d7-a3ba-58fb-804d-8542377fca86",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93c01026-d116-56a6-a434-b7f7efe4561a",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd222b5-8f41-5b19-a197-6c9dd6786700",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a50cc2d9-8bc2-5ee8-8353-9ced18ad26f2",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18932005-7f0b-5516-9841-eb95c945be71",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bc08cdb-9867-59f5-a5dc-473aec30c6f7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fa0b100-4c9d-587d-b81c-36fba0eba75e",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27fa075b-dce2-5919-b44b-10c0268b28e5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72d53b88-b18f-5c3d-84c5-49f33c18ae62",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419bcd8f-4ed2-5583-826b-e7ca74752f74",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235a6ee3-8711-5697-be62-49137635d378",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38829cb2-9f8c-541e-b4db-2c737d3ce7d4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eb50359-ef1a-5f0b-bd78-f769662c8147",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3a3454-1938-51ac-a9c4-3f93b94ebb0c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba8bed3d-8ba8-5de7-adfa-a7b1fc691860",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48639605-9d0b-5059-9c53-9c804f300558",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de4eae72-61e4-54f9-8f59-5a74ad85f536",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15cfd8b3-748e-57d8-9621-2fa45c6eb781",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c89437d0-322b-56ee-94be-fbc4cece0a52",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f76bdc5f-4d59-5242-8bb5-50f5a23697e2",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3ad633b-4f23-5067-b6a2-893c77c8b2bc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0526b2cc-5e3c-5be4-bf6e-61e8a856d92a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53a0d6e9-307a-59e2-9d76-8ed7f1878ad6",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a59a4732-3232-5baf-9d3a-2fc677aee5fc",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2157c3c8-7944-587b-b050-101a93ffc9ff",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:868b0aa0-450a-5aea-85f4-93f39162edb0",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62048354-c1e0-5be8-99b3-fa52603958dc",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b71606-d21a-5bd7-b275-aaa0c65ebff9",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:260f5866-b2a2-55af-9018-b1998d83a6d8",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@4.2.9.RELEASE-tuxcare.8"
    }
  ]
}