{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4eb19c2a-c3b3-5fd6-b8cb-db22843f732c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5",
      "version": "5.2.0.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c788b132-c654-5cfe-8c05-0775c616d292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1f4e886d-ba79-5eb3-9719-c6802b6fff6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:389a44ed-ef20-598a-b05c-f9f84988fa1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:03f75483-1702-567f-9c44-d682354507c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6573201d-9d97-5084-a647-c7f76acb6297",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:814da032-b276-50f7-b487-00cd37df89cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3445e865-8658-5bb2-8883-663171aa55af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:850b5f8e-7b82-5832-be2e-a7dafc632c07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:19b26ef0-3e21-5caf-962b-90e850e2980e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0c5ff35f-684f-544a-bdba-161b7c0da9bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f9aa1b98-e75a-5b69-95f9-93a318806430",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:385a383f-633c-56c1-b1ab-3f15f013e95b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:11e484c6-2597-5d91-947a-077f0b68f327",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fe524c03-e633-5a83-ab6c-ba946da23460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b5de68cb-d56b-596e-a23e-f9884efae67e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:29974f2e-cafc-5771-8d99-0aff88be13b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:677dcc7c-3397-5dbc-bf69-20e2253d3bb6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e0b8653d-c82b-5e2a-9a44-860459fce41f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:62a0052a-1f46-595b-a579-dbbc69ad0eed",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-oxm 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c2c6f63e-79f7-5ee8-8752-568098941253",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0e0467bc-bc24-5463-a49e-793cd8e5fdc1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e4c57749-5d82-54ad-bce4-98f372cb6922",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ac57221e-591d-53b5-9f1d-ab48894d4344",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5f1f702b-662f-5aef-b0b5-9c7b423639fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2801a033-8080-5c35-9fbf-fc4239196f96",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-oxm 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6b436e09-1495-5d44-ac8f-d8194128da52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8f367011-a45d-5f8d-92a7-0b508a540df6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ee1290f4-83c3-54c0-834a-c0e36531670c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:517a9e45-8650-5729-8b2f-c1877620f731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b5ec33c7-b857-514f-bd44-60d35e5f3fba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e62fc0df-cca1-55ad-bd46-89b282b17295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dae9de42-8108-55fd-84e3-99a3bc7d2fa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6f04bb6a-51dd-5255-85c0-4f96c39ab78e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e4df5870-d704-57df-bfbb-9491015026b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c51888c5-1012-55c3-8caf-d9e47a4797e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e31039cc-7065-55ca-b2c0-0324dab2d586",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3481a21f-0b79-5ab8-bb29-e283462b59fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eb4e4661-0670-51be-8834-c20555fadc34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f1adef3a-0b31-5e45-a709-a0080e16e666",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3952337c-633a-5d46-a058-5bae88ae2215",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:62350e03-0329-535f-8cfd-27743b79adb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3da1d914-31ea-5bc0-8292-3af305d3a1f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b816921f-355a-5822-a821-d2eb0a6a2eea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b2d31b94-976a-5220-8937-454223871402",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e0acc28e-9402-5787-af14-60ee3a39cc1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:18bfff8c-b109-5006-acc3-b5345e176249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7b9deb13-3a7f-5a59-9d57-e1cc1af05a09",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3045b681-90e0-5078-9335-6c7b7ac68cc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7ea36748-bbf5-5cc6-b3c5-2546f19e970c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7f65b702-4023-5f20-8925-eba831e9710c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b293a8a-9441-5a67-8c2a-36147d3e049e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1f25d302-2482-5f6e-9082-2d507b2cb77e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b90a4c21-a856-5b07-ac04-97a7b58856a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6ef9e081-008b-5581-ad88-ea5d1cbdf3cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:69a34e48-0e0d-5bcb-8876-f48271a1f0ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:946b122b-f720-58c1-aba0-8e88f3ed8a00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:39fdb61e-c570-5af7-875c-a59270430173",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:80351e1c-5c48-53f4-8914-0d458f6090ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a599d391-4b14-54ac-9aea-33073c5193a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e98a959b-149e-5d6e-b497-b87821bed25d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.2.0.RELEASE-tuxcare.5"
    }
  ]
}