{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:db2927c5-f8b0-5cf9-a10c-a4e9879972c0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2",
      "version": "5.2.7.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:801fbca1-0b16-53af-b311-f6c76c80c346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f084ad2e-e741-5992-9318-6200593d351c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fe2efa42-dc12-5e86-92fb-64f5fc1dcdec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:59f39d35-3ad4-53fd-b9e0-02a02a9d2f9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e252a545-c46f-526d-b90a-09b2a97765c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7ae016c-7925-5328-a9d6-6f2f7b47aac2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:42b137b1-02a5-5482-bac5-b0fa29d42a13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6613badd-4331-5f86-8291-c9dd9e38b552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2b55d3ee-b0e5-5781-a8bf-3acb19d0f7b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:57e5e1b6-3e65-5b32-a035-2a87649fedb6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2688281c-7bfe-58dd-a649-ef190ae4e876",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c28dc6b7-3344-587f-8603-043f5adea34a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dcab5abd-08d2-5937-b39f-01a97cfbbb86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:badcea78-8e90-5b0a-9090-ecc400e4da5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5167bf8c-d449-5416-a9ae-98482bbf75b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9dbae3f6-6bac-544a-a7a3-900477ea88cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a65481d6-723c-5cea-b112-606ce44b6149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aa745a92-89a2-5266-bcf8-3497b3518448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f6fec9fb-b709-553e-94d3-20e1f4d0f1b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17677f22-e14f-5974-bc89-f0d3ef5057cc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8a725232-40bb-5364-8c3e-64ee07bf9538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e3b3d46-a089-5210-adaf-24f07b08cd7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fbcd2ebc-a41c-5681-9af7-0f6182af610a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fff097fa-5861-5067-9ccf-070f799ada5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e9ad318f-8295-594d-989a-1258f8933b66",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:faa9f8d3-6817-543c-98bb-8edbfbfdc596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:990d50e3-5277-58b8-9e01-812ca342a9af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:52af682c-716c-5f3f-99d2-eb1e33d58ae2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b8d57b96-d83d-5e4b-ba94-f99191989f74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0eaba37e-e90c-5eba-ac53-88c3b604ad7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:428e4e50-959b-5c6f-a757-0c288d85c2f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c81305c1-b110-5951-b70f-50bedf6a03d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5f036be2-53bc-511e-8544-91be351e8b3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:170b1e19-6fdd-53b4-b254-19f6e1a1cd84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6d0c0830-0f20-58af-a74d-6da46e46b025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a0327ac-6d0d-519f-8008-b0822ff5b8be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b140f04-e85f-52b9-9ab8-4de426031415",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:77a9f8df-dead-5dfe-b87a-bf140e82bc48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:06916fc7-f2e3-5789-b825-7ef408d9b95a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:697c52e1-6b39-55e0-bd5c-9e60c81013e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0062fb52-dbb2-5abe-9d85-b3d3a545fcd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bbf89c3-cb1c-52ae-a70a-ff4b593c22ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:40e0efef-00dc-5d43-b27e-7be5e1114298",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e08de0cc-caca-518d-af59-00f20e4dde54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6b5fe3f4-ba80-5fcc-beab-c6d7c2dc45f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58be8197-d215-57d2-8323-341025445c88",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0358466-ab0a-5931-b9ba-3d139dbaba2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eaff047b-9459-5b14-aa71-c2a91c7229e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f24bda6b-3398-5c8c-a489-1ce45793d7e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45ccb514-3dc5-5ebc-b3e8-043662eb1f72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c31ef451-567b-50a6-8dbf-be9e6e0edab2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:baee8ca9-a68d-53f4-9fde-dc9e1a88145e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4c05a0c4-e7bd-5445-963a-e94dbfd6d396",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:06fef00b-5b69-5981-8b09-be924220d843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ed2ef651-bf1a-5b48-b768-ec2cc9822818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:68659137-0b11-5ca2-831e-8afb059adba1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1095a7c8-284d-55f0-863d-f62c78421b74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8f1517e2-bcc4-5402-a705-b1f61dcd315a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60800e81-1ebb-59cb-bcc3-3f541d7980b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.2.7.RELEASE-tuxcare.2"
    }
  ]
}