{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54dba8d7-6d13-5428-97b7-76c55d2f8e26",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-web",
      "purl": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2",
      "version": "5.3.20-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d6cf5428-c25b-5280-aa2d-db60d9ce31f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ef9b787f-230f-57e7-b28b-97a8215d9cdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:08d99d06-3148-5bd8-9535-f2ecba77dc8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2f3374a1-8794-5021-8cb7-67e721a844ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:44ec4340-7313-5f9f-884a-081244c662de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74af3008-c2de-51be-be01-10d29be26cae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b273189-686f-5ee5-b07d-d2d46afaaa8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43711507-1439-53ae-847e-e4f95fad6a67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:821c62fa-7cdd-5c4a-8b82-aa1472ed6137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32f1dff7-df77-5f70-87b6-8fc22eca6fad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e83562ac-cd3a-5e56-8a98-0511cb4e7862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ebdb8c2c-1267-57e3-aa7c-76dc4e6f5acf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:95e165cd-75e3-5079-a773-d539ac4897bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b395d6a0-8a82-59f8-b536-2b8cac6ded9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b94c9633-cd71-57f1-8fcf-d12c7b689b34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9c8308d1-1dc6-5b65-9d07-bbe62289e8a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a78e114a-a391-5f0c-b66d-91aae691da47",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e38ca307-9dc2-586e-b48e-3b7901b61c26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6c06bd5a-098e-571d-97ac-0bd7932ad2ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f2dc66ae-d60d-5579-a272-506d487f921c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fa8c9a43-f9af-5322-9fe7-be38ce64cb09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00564261-38c1-5308-91ff-f118434bf5e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0b03133-dfd8-556a-9743-13ae866fb02a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0a2e572-fc71-5aa2-bfa2-ede16e4a42ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5e92321a-574c-5c07-b3d2-090870a1618f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8782c93f-b73a-551d-a47b-197743aa3db6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:afdde9e5-8302-5178-9d83-a3d98636555d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:87c66f14-5467-57e2-a440-e11c58c0933a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f1fd5bbc-c35a-5a38-af33-8f30cd67f2fb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a55c031f-0cb6-5a3f-bfa6-b4b7dcaca7e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:336a0458-2ab4-568c-8165-ac297438dc56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:68beda98-b86c-549e-aa2b-5ce9797a763b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a482a8c1-08bd-5526-ba85-7d44f5cd214d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8cc2b1c8-1068-5e0d-881f-6a40ebce82b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7703f0ad-24ad-5524-9686-805c2eb45988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:70a313df-c100-5325-bcaa-a6225277fbbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:085b3881-d1ef-5698-98b0-32fb79b3fe2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4445dc31-55dc-517c-9ed4-c2927ce83e4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7cc9f9d6-dc8c-5f43-883b-b4549288498f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4b43e4bd-0f30-5780-9380-830cce774d1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bbc49faf-3bdf-582a-9590-c0896faac865",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e148dc2-466e-59f3-a7be-4065604eab8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ffd440df-fc35-5196-8b96-475cabdc693e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:978fe9c4-578b-5257-a2ca-fb3f1f7eee5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9f7d530c-ac43-51dc-acd9-b89c05a3a034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7957bf36-d2e8-5389-be61-9e8b504bbd46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00aeff06-7a51-5a82-8f01-efac71c93279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e378303-24cd-53f7-9ad0-6a8363042915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:48affdb7-5089-5ded-a4ee-ef484d93099c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:efc165f7-6c0b-5587-8564-c89660f79dd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ec5f1447-1306-5ddc-b2ef-6de0c72110a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0541710c-1a77-5497-9a63-5b2f1d479d0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b176e19b-128d-5109-a812-a6894f2907c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-web."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-web@5.3.20-tuxcare.2"
    }
  ]
}