{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:567d9228-4d53-5620-8e2d-8d3c48435ffb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-oxm",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1",
      "version": "5.2.7.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aab4ce2a-29dd-5d96-9d9d-1e82181fbb33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7496aa6a-ddfd-5fe9-968c-d4ba33b06509",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a6124cd-d360-56c1-94ee-e7f756a5ae39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:43ff0f03-2d35-542c-bd65-b42e4c6cfed8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:60b975dc-2f4e-5388-9c2a-d9a24193e866",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:05b4eefa-e633-5099-88b0-d2a117635040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2fe0a633-8106-520d-bcaa-f33b9578b5b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6a5bf689-a17b-5779-a939-d65221f9479c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:885f4178-104d-5304-ad92-a492b40c20b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9d23ce17-fd78-585c-80cd-667cdedad3f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55db81f0-c0f8-5122-9f97-faa870e74301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a57aeca6-dd3e-5048-930d-fab58f889406",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:919ef274-5d39-5995-a2f2-fdb92da42afa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72963669-a7bd-5e43-a5df-304c9b0c63ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5ed8887-0b71-536a-982c-585fad0903fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:989a6a19-1dcb-5a58-ad26-ad505bc08504",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1a8e4c95-feeb-5731-ad88-f67df3822950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89d8791c-537b-5ffe-a790-460ae9f6d27b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e49b42f-c923-5f4b-9141-637e4fa28c13",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:caeab560-2b34-5a04-848d-d4244ec1bf9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66e93712-012e-520d-8496-8be983927879",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c7da94f-7cc1-51ac-921d-c1907efdebca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1c1e2897-da5b-59a8-af2a-e70cbdd3aa8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48aa3801-3951-5fbd-bcb3-0c143f260a1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:594b1c6e-ad76-5d0d-af58-810083438f06",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b45600c5-3b98-55fa-a097-d1a1c53a132e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5c87ea7c-e0dc-5fc5-a55f-c700960e02c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:42c180ed-68c8-5392-a0b1-fedddd14609b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eaf74ec3-016c-5088-94c7-a2ecc0cf3e7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f08580c-a576-5949-b350-790a37bc1cf4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:639efcd7-31bb-5fcc-a6ea-7a5661bec672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1374782d-da06-5911-aeed-50d4ffbdd368",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bacd56ab-5839-5a14-9ece-1f933cca9c63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a74d2061-4bb6-5277-b81c-d028d1a27b19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a647d138-701d-5668-87ae-257e7b25a4a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ee73458c-2507-5cfa-b63a-5bde955bf2a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9b34cd5-9c9c-5783-87a3-7ab04a05254c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d1da77b-bc18-5782-b89e-496279229fbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd98460a-3454-5669-aa2b-5d869dc290ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:108af14a-27da-53c6-9510-da2687edb218",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:603fdae9-0389-579c-940d-393165e0ff4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5776ce0-a8b7-50c8-8572-45956867e809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b23fa461-6063-5f2e-82d5-b4a9a10530ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2adeb76d-f297-5a16-aede-9d33cf374dab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a59ac9ec-09cf-53b8-af5d-1185bb3a2d44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06d1fbf5-8962-5699-9c47-20130dc72ead",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16c78269-20ca-594c-a654-62a64ddc2b0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4cbeebf-f5f1-5d0a-be1b-2da535f3ad9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7dceab4b-dba3-5569-8d51-800d78502852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fa4c9445-15c8-52a3-b400-ab742c5519c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef6edf6e-bd5c-5a50-af7d-8282d8d277b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fb7e9f1-c112-552a-99ff-12bd09c7a0d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:514a1304-5fc6-55dd-938f-3fbc52f6c54f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:550083af-83d5-5188-8b7e-816a52b4b3ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae97ee68-fa50-57a5-a64e-c039410ca0b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64dd4765-984d-59e7-bee9-af1ab7693df5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0139b67e-8604-551e-8669-6dbfbf6d9271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:08c66b6c-f65b-582d-b9a4-b8ecc6d811a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-oxm."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.2.7.RELEASE-tuxcare.1"
    }
  ]
}