{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d93ca711-96dc-503f-a2fb-ebd356ffcdae",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.37-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1a27299b-0e39-5736-8ef2-5f89929ffbff",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbf79b45-e216-51c5-a26c-6098642deb1f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:551f0f03-1936-5808-905e-bcb8414e8915",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f656fc1-b57a-5169-a9a9-a37409a8941e",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9ac8294-4339-5d8a-b193-8bcdf2726f17",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d01f21f2-7dc1-5efb-89ae-39fe0e03ffcc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3215ee54-2810-56a2-9d08-9c144abb62c7",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:418fbbb0-aa21-5e34-b44b-025c8b3a69c8",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e5b4e8c-8845-51f6-92a3-115e802090d3",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55e404a9-fcb5-58a8-a4a7-4782d8ce847b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:defefee3-a561-5e69-9cec-8b412929ea25",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193a547f-0eb3-513a-9c73-4fd9e6c5b060",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3baee0dd-8a3d-5e5d-81ff-a18e1aeae4c6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8357b0cb-8548-5b8c-bc54-12a00593433f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb6a7f97-32ad-5e34-895d-8b6a2c5426a2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a53615ae-8945-5780-be1a-f0ceb005a950",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e13c039a-e54b-53c7-a1d3-1af03a6d0ed6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dee91f01-2b64-5db3-abea-9738e82a25e1",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65b7ef95-9928-5921-ab76-a157057ee7b8",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:769caa74-6afc-55ac-95c9-8831dec44506",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e645a460-d10a-54a5-b8a5-2703646257c1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e3a6fc-4939-559c-975c-5fc3fc7d4dfd",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf30941-7082-538c-9439-6b29c535abdb",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5675351-84f5-5852-ab58-9572793df66c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b58461-7a88-5b04-b5cb-dca632831950",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff9d2484-7f8b-5d3a-9e58-2dce1bc538ce",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22a4889c-0cca-5542-8646-273da287a4a4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47ddb498-ba5c-5e2e-abb1-02fc67a2b051",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6da2f81e-3173-54d0-a4c1-1e060c9eb95c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e538179-9e79-5420-98f0-b0406098e38a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aee232a-de4c-52e6-8494-8e92a894dfad",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:545a84bb-82a1-594e-a728-f18b56edaa0d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d26b38f4-aa9f-5a0d-a156-184a0e123a9d",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2528f4c5-2a67-5099-bf33-2f499b871140",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7075829-7698-5a2d-b48e-ca0c0a0378a9",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7ce1f79-ecbb-5afc-a675-606d3633eabc",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df093899-9673-5648-b90d-8461f65ba85c",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d49b9dfd-fca3-5016-bd8d-a6c0bfe3dfba",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d160b2-fff0-5350-8600-fffcc54aa73d",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e48d67-7ca9-5707-9ac9-2af90c2006b2",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b8f1e6-8717-50bc-bd4e-a40fd6d2e557",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d5f7f8-d93b-5a71-ba7c-c11a1b8ea28c",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d59c12d4-f34f-546c-824f-11b73a9d2fb0",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c6aa47e-6b12-5516-b8d9-c42881ec8b7d",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bc3d248-31eb-5e72-bee8-085ef80301b0",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f5a48ee-347d-5d92-88e7-408045501f23",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3142c2b-cf8e-5580-a125-654ecc087eb6",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.10 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.10"
    }
  ]
}