{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f1abb8ee-a22c-5ca6-a362-69e0a4d8c03f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-jdbc",
      "purl": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b9fdf23d-7681-5bcb-a0bc-99b6cbb32efb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc39c18b-6dde-5651-80da-939e59fe0497",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d4f12a23-5c73-55ee-9629-1026fa4dd5d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f354acae-122d-5a9e-a82b-efff60793b53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a244cf7-d56b-5ddd-81cb-273d684c1293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7174e901-ac35-53ef-afb2-63193028a8e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:beaf1976-4cb3-5a05-ba83-fd7ccb59adae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f6c04386-6d98-5f3d-9287-74a58904c481",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7cfaa01c-9b97-57c1-bb24-9f387c494724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d709b738-2392-530b-a21b-f06a14ff6c26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e15680ee-75ab-5d0a-9c1a-093e542a3d0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6626c413-80b6-5f4b-839f-b871e902bd7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32808925-898c-5287-bbbf-37e0e87101f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9108603d-38e7-5584-85e5-6e009ee4f4a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d62108e8-37c1-54eb-b1d2-81904d535e83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37b735a0-1428-59e1-908d-5eb7797157ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d70705e-30d9-5805-94d3-b3ee568e406e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2eb4f7c-5829-5b97-93bc-5cc1a299bfc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:61b7aa25-7762-546b-9479-28b6e423f19d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9d918706-5d13-5065-95ef-04a640431285",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59730044-5ec8-5cb9-a4cd-ab806e4b0da5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5fd6a5a2-790d-5569-9626-6e0c6fe6c583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e75acb54-e5ac-592f-8d6a-c858504dcdb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18189cb7-9ca6-5f17-b751-a1fa3800a766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72875ee2-3366-510f-8191-f24ea23f521a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d704e192-1e77-5517-83ed-c7e2819b3912",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55c10966-cdf0-58f9-b9ac-4eacf6659230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9cfd3061-8712-50a4-ae03-d74ddc7aaa25",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:536dd501-7e85-5925-aec8-38c9a6f31292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5efa63a-f5e4-5e19-bced-6327c8256f39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da3d77a0-0d9f-55c1-9a55-1608b8221a66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8992cce5-53d4-5ffc-bad7-14d4a97f573b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8b02fc5-efcd-51ea-90a0-1f9b7810356f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c049067-1ca9-558f-a2a0-d959adcb83f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:300d6100-b999-5994-aaba-c4513041ff21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46810543-36d7-5fbc-aae6-0cb9ef34a201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4da74608-89ae-5d5c-b726-034ede7c7b42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e1030ee4-ee49-5e4c-b854-12679aadc4f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c4e687e-a6aa-5c39-a821-0e613a6fb188",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:636bab35-e116-5911-aa76-3b8c06983074",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28976b27-6512-5652-a7d2-d693b502ee6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc074e79-41f7-5a81-a6aa-41b05ed0c3c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a13c5418-7018-51b1-b637-e1523e14e4a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40178d28-9881-5f2a-bd52-a6e1a0a4c1d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81a12569-e1de-5589-950f-a9221d11ecce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85887bd0-8917-5355-933f-358e8d787ba4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a4a25ad-352e-5ea0-900c-ad8c54645845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5176a97c-9b5d-506c-b522-34dfc24e6438",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8df97cdb-36cd-5da4-8c3d-99f17c4209c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a6062a3-26b8-5704-9fdb-8ebcf916afcb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4386c6a7-4f1e-59ef-bbb5-b97d281e9658",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:070c4584-59e6-55fd-a33b-ff4589e9acfd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:814016d8-6d40-55f5-91b0-bd86eef93d75",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32c23eb2-5bfb-52e8-bdd0-e12713d526c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc7b4275-f90b-5877-9157-ea12c79b84c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fff0fbd9-57d9-5580-9491-d5dc27714100",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fd58340-bf1b-5638-8201-9b802e60c006",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8063de51-5b87-557a-9938-fe595f0d38c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:93041a67-81a5-546b-b24c-945fccb8ab6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:14cc927d-3938-5c7a-81c7-92ce7044050e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad9493b8-32bf-57c5-b9c3-912abae1819d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-jdbc."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@5.3.6-tuxcare.1"
    }
  ]
}