{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e9e16d3-9bb2-52f5-b410-bc3c3f23c0d8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.27-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4b669cbb-2f50-58bd-8adb-11c01e0d0026",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da4879df-61df-5a4b-9744-3de50664ef29",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7db5192-7346-586c-82ac-750e7cff847f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c3da401-2314-566a-9124-f4f2c5e11e10",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce4ddb1-376d-5ffb-899c-e7a494ffe452",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9afd990-9d81-53a3-bae1-a04bff5fd22b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:445f9964-9473-55e6-9a78-da918f93e866",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd4fd6c9-a964-50ae-a6ff-5d08b0c3cfc1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6008b55c-402a-5a7c-9c85-19d036029ceb",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36987aaf-f088-51ea-8cd3-dc8a99154d8a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81f2fe69-9d2b-59b4-8d7b-97df6a35c5a8",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1fca54a-c9e8-570d-9797-5b99183fdc85",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-framework-bom 5.3.27-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5461df4e-ca9e-54b4-a86c-ca4f262aa5b8",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb42056c-65b1-51d3-a499-52d8706c6a81",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e1de314-6c0e-53da-bd5e-d0c5d46b8417",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb04cbac-9e09-5dc5-8e74-60b23505858d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ff482b0-52fd-59e9-a7f0-4eec236a594d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9c8bc51-6f7b-5cbf-822d-3e2499b52d31",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f7e0e32-d5a1-5892-bb89-0e91e92007d5",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad176d82-2428-58c7-ba87-c11cd8e6af75",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12618455-b3cc-5932-955a-f6ab7dfa9e92",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9084a9f1-27dd-5e3e-a803-07b8d65c17b1",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e57809f7-4af2-51a0-8054-7e88a80839b3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a004758-a9a0-52f4-978f-ed5e2aa6aa42",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c7c1f57-21b1-5abc-9d74-48cab68ce517",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eb66af3-21fa-5388-9878-d82674259879",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32ff44f4-2ba5-50b4-a4a9-c9ec52ffdece",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754e98ee-3a0f-5264-b423-b0fa882d44f2",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:872ba063-8d60-58c1-8c54-308698c94a4b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d7954b0-cc2a-5b7f-8e06-f9e59fcff9c7",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88ba03ff-43c3-5aca-9df5-3a17f6d51579",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1e8bd2c-7560-57f0-aa08-1b4c3e1a68c5",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41c6f2de-1950-5898-bf4d-48d75deac91d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8567c3c4-4d0f-5d06-aa06-a0ab1ca85940",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d79498-b2eb-524e-9f45-c12707084a70",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6772e44-f337-5ecc-a39d-594127a554fa",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4532c125-0edd-5031-bd2f-c02cee2c0313",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35d3b61-ba34-553d-95aa-a53697422695",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b11627-fd13-5d7b-8240-a7fec1787052",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:937d593a-3d15-5c75-a257-bc6773835738",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfb213f4-aa13-51a1-846f-513755282df0",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8867b5d9-d91c-5b56-833a-2cca5095ffdc",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9309e5c-587c-538f-8bcb-c9a3cc930f68",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c37e2d-ca62-5952-b5ac-30fc11657b80",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34b86059-017c-5e6a-bb66-cd72d6bb66f3",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13bddbbe-83cc-52e2-8387-e14c59f31090",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d2283ab-0058-5998-b2f5-62d614155f76",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e37967d-7696-50a5-ab85-476c8aa6e16b",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09a5c87d-e48f-5741-888a-75762954b2fd",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8721378-dbc4-5271-9c78-67b16523983b",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b85c39f3-d9a3-5122-a932-bf3c794acbd3",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.9 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.27-tuxcare.9"
    }
  ]
}