{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:69f59fdb-415e-5972-bcf5-e4e3c3adbf4e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6",
      "version": "5.2.0.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:171faab9-d019-5aa7-89c0-f05b33b68aee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e6e67478-921e-5828-b2ab-d49659459631",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8346b021-d321-583b-8478-e0dd8a2e4f07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c62b127f-d3db-5d90-aa79-46a64d204893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b1657ee3-e295-59c3-9cec-727500541aca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b37cc398-bec5-5292-8125-e37f19e6e97d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f9b59776-c58f-5bf1-bcc3-362b6f948df1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4c677d8f-44d8-525e-b4d2-468b3dae298a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6562de1b-c89b-5f26-b193-d3779dfc08b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fd0bdc9c-b00e-5f31-a29f-82125696a090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2f9d6068-fe05-507e-8fcd-84bfd5af239c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3bae565a-6ace-5c7c-9b2b-bdf6e992eb14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f1a2732b-1cce-5a04-80fd-2ec7512c4714",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f3dc4bc-f994-52a3-bd0d-9a251d7d1729",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a903c8ec-eee6-51a0-8215-c58f67a241f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:197c5679-96d8-54ff-a863-ee6a8c23b168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:001be872-3bda-5eeb-85a1-834997b9f09b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1019afcd-fe76-5aa5-8188-6fb0ae2a5442",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9270bd56-f516-5756-ba7b-dbc3c3b086f1",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webmvc 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:84745ddf-a5f0-5451-b777-953de4329b14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4e169ceb-96f1-5a11-b6b2-068d15895afd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3f795c16-cb7c-546c-b402-017b8cb705c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fefeb548-1028-579f-9cef-0e93f5e3cfd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1d2962b7-c72d-5d3f-8c31-87b9616b12cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:55011b07-2286-58e6-9519-fabdd599cb15",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-webmvc 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df5af150-44ea-5a94-8f41-836dae5a68a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c1724f7a-2e79-552f-8492-2dc6d04cdcc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c67db791-5816-53aa-9ffa-9a8aab0c7cfb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3ec4b6fd-4bc1-5634-b6d7-68024ccf5f0f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b541c8d7-771b-5238-bbf0-1339a7762e2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:530388fd-dd0a-5f73-a1c2-262711850da1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:34d0e6dd-4a29-548e-b6f1-9b494863e803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6b797fcf-4b7e-5ad2-ac1f-009f01b0a6e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:49ab2ebe-eeba-5c35-a4c7-d6d693b70d3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:29418a19-2c43-5fbb-905f-7c9757dd40b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4db1cb65-91ba-5a80-b0bf-b86f2ed45942",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8322b2c3-bf58-51d2-960f-25dd470ca4f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:820ab4d2-7c72-5f90-af4a-4013fab7d47c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:735e2b95-3130-597a-bd2c-eb78d6d563fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:387f30a6-8e1e-5de5-adda-3bc5e31ff76e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4ffaef87-c91f-56e7-9002-311a11316fd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cfb7c3cd-9677-58be-8a79-31cb3c6d52c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ba6e75f8-83e3-53f8-a8f5-0a7f6bda9bcb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ef6f3a7c-0297-57b8-9f28-da299c271073",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4989e420-ac6b-5ae2-b72b-91802b12c570",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:12a2ee8f-f93b-55a9-910e-069aa2dd70df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:34cf1974-2eed-5293-9fd0-4343af6566d1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c2d0cdb1-965f-546c-a3ca-356634c6600f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:85e70c6f-2612-5e2b-a6bf-80c19f90c2a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e129839d-eab1-51a4-a921-feb7b6396fda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:be0d898c-13a3-509b-8b29-e6de43b76b9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bb22323c-5bd6-53fb-9cfe-fa0c39575b7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4bb13edb-027e-570b-b3de-bedf88c3c8fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2727198b-626a-5bb2-8f1e-8479bc42ac07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b15fef68-75d4-510f-aeaf-1e8eb57278db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:09e4ae4f-3822-5fae-8cb4-6afba991e595",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2f4a8bcf-2ba5-5b43-aefd-add26de95e34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:459200cf-c712-5d73-84f1-bedad4271317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3a882473-3587-52d0-9498-a1fc5782d7df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01395688-057b-56eb-afb8-3cd430766f9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.0.RELEASE-tuxcare.6"
    }
  ]
}