{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:62d80d1e-d4fb-5d12-8103-56b18b95a387",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webmvc",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2",
      "version": "5.3.33-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bb754b30-81f3-583b-b610-62ddd9a376fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:219cf947-efc8-5b43-b4b9-e1dcabc45f5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6c012646-d503-5cd5-8b74-a38b498b88e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f0080c1-8ae4-5af0-92cf-240e8a270b9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a07ef2d2-7eb5-510c-9e55-e3d9b26e679c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5d48ff65-9c25-514f-83b5-7e6fa2aaaf02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8e298e35-6a8a-5c68-81d4-2b512c54eb3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c4644728-9597-5ec6-8bd6-67062693ffe3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e540157d-8208-5ff5-bccf-c1100e9ecbcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a11e5d2a-94ee-5af0-8e4e-6bfbf9e7c260",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:640ac865-899e-5a76-88fa-9377a6864eca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3b3021ce-c25a-58ac-9473-1babb8496963",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7a601ece-722c-5b59-ad62-197e42266b6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:79fd6f52-50c6-5096-915b-c950e1b4c305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38868315-4bc0-5792-a353-db7ced979281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:25cd4895-a551-5063-9b0a-192978f77317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4a6640eb-cf1e-5992-9d97-ed530afa0901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e61be0a5-a41a-53c9-8663-b5f8080ef40a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3609ce79-7e07-5fd2-906e-04ad4586f5fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:756705e7-d68c-514d-b2a9-8fcf63e9bf05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:29a1ccbd-c8ed-5a9d-8a8f-1ea9596acb86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0e0f759-0553-5b27-8594-1f33f917189d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:522d7f70-d5fb-52c4-accd-1bf380873241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:34709614-e2a7-56e0-9635-9f52f53994e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c939d91b-8825-5f14-8d4c-a9fb80877b50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7fa524ae-ccc3-54a5-8c0e-175f8a52d5c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bfcdb86c-30fe-550a-b8f0-135f28567417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3595e50-43d4-5858-8e25-87a3f3534c9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e84ff71-1457-561d-a40b-442f50cdf576",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84515fe8-5d31-5cb4-ac39-8a0f6863101d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d77afc55-0886-598d-a1ca-a824ffb9909a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c1f4d4e7-cd34-5b8c-a5cb-7e50cca091ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:374c3649-3fdc-545d-9ee3-8093af264bc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0aa1a482-21f2-5b34-a544-81d91962b36a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7f2660b1-1497-5ac1-8544-3b7aa494b3ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58bcf2fe-ecc4-50d3-9336-c427299b8833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:820d8d28-95b8-5747-921d-169d520bc077",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f92d82e8-263d-5b59-ad40-fc7fd5c1132f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bdf7ac2b-2415-5355-9034-fbf139d2d6ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:82de68e0-25c4-5759-9e95-0a545ca39663",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8884d116-8f54-55a3-8553-c69ef630e90a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d0e97d2-1a8b-5f2f-b33f-4600a66603f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b926c0e1-949a-5c5a-856f-d9c060aa2437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a6b60c66-ae19-58ff-a32b-44803b5b9dd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ee21f6c6-fbd6-5ae8-81dc-e38ceb91352b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:27c7c8f4-b00f-5e47-9d81-c199814d21ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b3c92d9c-f2c0-5850-acb5-dc74c92a431f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:922a4734-536d-50b6-9fe7-4aa7c0dca214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.33-tuxcare.2 of org.springframework:spring-webmvc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.33-tuxcare.2"
    }
  ]
}