{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:982225e3-910b-574b-a6d5-7dd9e9a84cfe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-framework-bom",
      "version": "5.3.37-tuxcare.11",
      "purl": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0887cb34-8e7d-5b1d-8f31-bd2ba82fe697",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b9d3631-1802-51a7-8473-f268e9b878f7",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f8804e-cacd-5aca-9fcd-7908db41ecc7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7452884c-03f3-535a-957a-357423de3666",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:327d3c41-024f-5263-96aa-e2527c39ee01",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3af591a-ccb4-5829-bf44-b1a6f5b19c98",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9dbdbc-64be-5569-9662-16df50d003f5",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30d48cf-ed75-5d55-a96b-01696b89a6f8",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a7ba7ce-f6e4-5bbb-81b0-d71ca14c2831",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e3175d-d61a-526e-8b74-55406c469ffc",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3132ccad-49b8-5c13-906e-ef360a740983",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ceca67-c70b-501d-92b3-3271caebc64c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7634616-09a3-5bd7-9729-c74745c4a9b0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67942954-63b1-5bc1-a0c2-b5f746c49f12",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daeb1ba0-b908-57ae-ac27-994014c84010",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e7b618d-05b8-5ade-ae8b-46d8e9a72b79",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c4c887-8cf0-5dfd-97a8-6a7819c090e4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35c9c070-a6cd-5a7e-ac08-c3ac8d83a70c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d21aa8c-33b8-5e3f-b4c2-f26e0fe1b683",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cff6434a-7cec-568b-b124-8345685bb706",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6313bccd-6db9-50fd-9d57-11de6747519f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:971f44d9-8bd7-5258-8bb0-904dcb4606c2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45093e60-e1f7-54a9-9b75-311cd486b3aa",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec1eb825-abbb-5868-b292-5493bdd61845",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2321e697-7272-53c6-a16d-8f03fdc8ad41",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c93ba758-3e33-5944-b3fe-0d40c2b328da",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eed83915-3bde-5c43-8b30-130fe0b2b36e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31a3279c-a98f-5358-b813-86fc7c1d470b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd607a7-6ebf-598a-b5d6-983e1f083077",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:854d3e38-3812-5e2f-bfac-5e8b9a28b89f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad83de95-0fc0-50f4-9450-9a0eef30e4c6",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a38169-b5cc-54ac-afba-38131ab515d4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9f568a1-e4b2-544c-b2fb-b504e6c79f31",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49602e12-ca7a-581c-8974-1bc890115927",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2034a03f-7942-50e8-b166-f5f41ead5abf",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d46f3eb-1ef8-5ade-b864-2c985cfb640e",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c95a1d-4781-56ff-ab45-ace11f27682a",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cb8c81c-101f-502b-8642-8f7a9ef1c125",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df4a630d-223f-556b-9d09-f349fbd65060",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253bada7-41e7-5f97-b5db-36a57bbb687b",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26f2a1c4-b966-5a14-82ce-d422b35cb84b",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2350791f-7798-5c40-8499-ed5d42320b66",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01a9484-4823-5c7c-8dff-38b5c1c49942",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c65de3c5-e377-50d0-b412-c6f2480f2a2b",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1895c6e-a414-5306-b659-34397678e626",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:801e5066-e1c4-5cb9-b3c9-37d5a38098cb",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8426a185-e9f3-5a7f-9b1a-5fef5ac11323",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.37-tuxcare.11 of org.springframework:spring-framework-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-framework-bom@5.3.37-tuxcare.11"
    }
  ]
}