{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1f70bf6a-8ee6-5f8b-804e-56d6df802c1f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-aop",
      "version": "5.3.27-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:20a99ff1-bd63-5450-88ad-5cf7b30ea404",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47b38974-9602-5f05-9277-d494fed92b6e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c428300e-7e3e-5e45-a277-fa3649fcbf9c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b3ba20b-68c1-50de-a952-33dd6c7b4617",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d3f279-3145-53d4-aab7-55b612067e51",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc276f0a-7685-5b77-b808-4f8735fdb875",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:040e11bf-0070-5263-aad9-d0ed7fc104f3",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bdfd89b-59d9-55dc-ad38-a1bd70cd7412",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cbdd361-bef8-548c-a313-122929a258ca",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b97ca80-aec8-5603-8ac5-4ed7ba066973",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f754722-fe7b-5662-8bf8-a3738438f909",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cdd188-c37c-5a84-87e8-27d2622d6478",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-aop 5.3.27-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a796b94-6231-57b8-9ac1-abab222cfbc9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9e42ff-53b5-5486-a15a-496130b487db",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cfdfc75-99c7-5ccd-9708-8bc6f4a63edf",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41e920f-5541-51f0-bd77-5a2f349e024f",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:014af8d6-d048-5184-8883-f7f2b2d570e9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc607a0-513a-50ac-ad3b-1b46b995bb26",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c2ad9a-3ba5-5972-89bb-b0658a71062f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55bcbe09-3303-5a1c-ad6e-3cd2a92a7dd5",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeca6672-2090-598e-8e20-1752f009f2c6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4af649cc-51e4-54b5-9efc-b064569a0dbd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:943113b2-e39f-5d71-81a7-ac366e760185",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-aop. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d31507c4-6582-5042-991c-7d003741c607",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f4862c9-004c-5e4c-95f4-636572816267",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87dee7f1-bf45-55e9-af49-4383f3a0fef2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0672a5d7-df72-5a7f-8a59-b56cbc8e2027",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81198569-5324-5136-8452-77e6d34fa8d2",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa2cf940-d60c-5bf5-a8e3-6a612b1d440c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ce8d39-d305-52e0-aef4-44a5cc2182bc",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-aop. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35e20e0e-ccb1-5804-accd-547aa1ef3bca",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20686b0e-41e9-5e42-a1fd-8705bf533fdb",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70a165b1-b745-502c-ae5b-2e7a942f0fbc",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6f5e863-d6d2-5169-b43d-fbe7460c34ee",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a11779b2-c26f-53a9-a076-dca804170190",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d618a5f6-59c7-51cd-9bb5-d3cc500f8a9c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11b71ba0-75b0-523c-8563-fade4e3e6160",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5543e2ef-dc44-5df7-8bef-eb36928dc32b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c63d5c-fa22-564a-a942-bcb6a22eac88",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c7e5f7a-adf6-517d-b90f-f7aa56ad27b7",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c070826-5497-56b4-8b34-003417fee649",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1f8e58-764f-5981-8f74-6bc356580daa",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4402b0b-ff71-5467-81bb-4dab4cb4fe2c",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df259d24-4ea4-50df-9eb6-22e348796146",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed1bb8c3-a92b-55fb-beda-e40832ccee0f",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82adc28-d87b-517f-be1e-3f6b9eebe6a7",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45aeb1bd-ecd9-54d3-a560-bec37b78e30e",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c71803d9-4cf8-508a-9ccc-b1ea875e9803",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd0eb1aa-fe87-5506-a76d-bde2749531d9",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5160d0a7-0ab8-5173-be8d-570c8e89a58e",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70562937-2849-5435-b53c-63c3681ae93a",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.8 of org.springframework:spring-aop."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-aop@5.3.27-tuxcare.8"
    }
  ]
}