{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13410945-142d-5b3e-b6e3-d738a609f6d3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6",
      "version": "5.2.0.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:09e9853c-8dd5-522f-b30c-a63a830c9c81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fc72289e-7791-5b77-aaef-668006f65ada",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ed0de946-ffa5-526d-9039-8e23c6717b6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ed64f0c5-c7b7-5a59-ae2b-382b7ac10630",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bae37fe-11d5-5f7c-86a1-be75d43d517c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c406d9a1-5b6c-5cca-819c-9562b3e7d8ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e83494be-81c5-5c1a-8c74-4a8e03b6c2fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bcb76e86-e470-57f1-92fe-ab0a3ab063a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1842a823-9e70-56db-bc98-327ac2c86c7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:577d7fc6-db4d-5896-8289-3cd447687fce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c2100340-c431-558a-9c69-395454225c9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aa96d36b-7261-510c-aaa1-98963dadbf72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:eb0f494a-e854-5751-bbf2-cf0efcf5e8f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5a242507-f7b6-59a0-bcb1-797c17adf5d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d1e42896-6d1e-5bd7-85c8-4878a26560d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f3e1b16b-7892-5d0d-a8f5-f8cbfda482a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cb0bf2f1-0beb-5521-85b1-a723a274a1d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9038200e-3be5-5343-892f-56f34fcd955d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:63cb3e71-27de-5ae4-aa21-8afed67a5362",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-web 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:28202359-93da-54ec-bf5a-dd1b6a3dc54f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1dc4450c-c0ca-5ee1-928e-bf4a42856795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ffe7f315-ae19-5c50-8e40-4381615d372c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f64b3d03-4ebe-59de-b6bf-c601cf802a7d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2176d2bb-35de-5faa-b542-44012a64af6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cf9d8a18-8f46-518b-b2b6-055288da6267",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-web 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0289ceae-a2dc-5712-833e-6722d5aaedc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5064de1d-7f8b-5feb-8377-04c38e227d0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1d7b6b58-90c1-55bc-891c-5171c9450dbd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0591da37-de83-5079-98eb-e283ef27ad01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:762dd982-ca67-54ce-bc7e-3b8373855a51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7dfa7f01-ec16-57a5-955a-e02232ac45c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e1d46919-e61a-5c56-a46c-7f03c9308acc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7fa116fc-f7e2-5ce0-9a1d-b2a694201d11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:98c05e5e-6645-5f2d-a872-a8db46596b28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:09c4ea3b-835f-51b1-a6ce-e49f990a769c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:87f7866f-781f-515a-9ed2-3cfb6845fbf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4113cf7a-e2db-5f28-8c21-4764d25eca1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0be7dd10-6662-5915-b7b2-6f64e8cd773b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:865e6877-8b4e-57bc-b3f1-b6b4fd1e15d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2bac92ca-923f-52a3-9298-bf27ed996ed9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:90a2be2f-5b2d-5e6a-adc7-0f0128d1bca0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2db1cdd8-71f8-5fae-9c51-066754913d72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5fcbcf28-e601-50d0-bf21-d2b817b34b4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5a4ead29-539d-5fde-b880-b50fe765f12b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:51e115fa-4513-5a7b-9f6a-0bcb3ec76880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4ba7cef4-ec7a-5627-81b8-c74191023b9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:21751c13-b353-5239-b4d7-7127ade340a4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:16ba4bcd-affa-5027-8f76-4a937e63b098",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4725ba01-34c7-5611-9dd2-5a2e41695f42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:36532349-ce3d-50b7-b430-b7d1fe89377f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:567c4617-2f65-5d2b-b4e0-e65ce49f9c89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c07f9c1b-75fc-589a-95c1-48c84c260c10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8a92844c-4a04-55af-82b3-29909ff37319",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9132da5-c71d-5d86-a373-684910f028e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a42b8a47-bf99-57e0-84d5-ad6c0caee886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4edaad0e-aab5-581a-849c-14f9c08f3286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:527fd5c1-57d3-53e3-bd36-1721b24aa536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:50240b09-45bf-55be-9c7f-35d0e43aea7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f0fbe7b6-33e7-51e9-926c-e54d6e04fc9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:73daaffb-bdc3-5b20-bc31-b716a22155e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.2.0.RELEASE-tuxcare.6"
    }
  ]
}