{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:231fcaa9-0d31-5b7c-b221-49b5df9697c3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "4.3.30.RELEASE-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:96875bcb-cf54-5139-b200-721dfd360087",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d2f2f81-de4d-5730-94ac-12465aab7c67",
      "id": "CVE-2020-5397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a1c7b1-5cc3-50b8-8fa5-eee36745de2e",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8f95a59-7b65-54b3-a3ed-3340dad154bf",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab23e3f9-7cad-53f0-893d-c2dadc76e2ea",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749a73e7-6794-56bf-96eb-524622f83d0c",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20453658-28c0-5a29-a22c-4996b053e5c1",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5163efb9-5db4-53b4-aa4d-5d4405844386",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc58e9c1-db79-5049-9843-3d13294f5a54",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3b1602e-57dc-5156-844a-14b70aa1d9a7",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aedbbe4c-a5fb-5522-ae79-924a23e4901f",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cee72f1-debc-5f1e-b525-95c3e78ee10f",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b480479a-e758-5e2e-9ac3-7005f13ab998",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31c68e7c-459d-5133-b5c0-1e2888e62af4",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d9775af-c752-5d40-a980-51a4b40203ce",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:365dcca5-6af5-56a6-9edd-7a321c50372c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e682b1f5-a73f-5f0e-9114-813d47d194cc",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92db6e02-a418-5cfc-ab0e-b9ad043451f9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95e5ce22-6ab9-52f6-800b-0adf2013b7b9",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e78376a5-b449-54ce-9394-4d423ed3a18e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2070e0ec-1da8-5e37-9dbc-2398fd982e98",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:312355af-2a69-5a68-b6df-dbdd128473a5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e254c8-2cd9-56b7-9dfe-1626c674ce05",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66b42c2b-ef21-5232-bf27-fa3f9a4946ff",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b7d670f-e11a-5b4f-9473-bc9e0f55a2ee",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da29e138-ebb6-5614-9ef1-1a95b1a11078",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2737e8c-fe17-52df-8983-75d395eaadd3",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6d654e-3dac-5561-af51-3e1f8fc2fc20",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f723f79-5e0b-5168-aaaf-f71b74b9c3da",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:330bf309-0aa1-5573-ad36-627847e4e58b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e11d7727-2c56-59cc-8414-a1f63db3e9f2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc26713c-14a7-5045-ac92-30fc0e6c4116",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9cb3b3c-cb52-589c-af4e-f230c57ccb57",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c941db5-4379-5452-835a-76f91e87e41f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f80af8f-3443-5a4d-9080-50a7aa36ceeb",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d760fd75-55f9-5bf0-8781-10b42b408f98",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a51e3b-36fd-5343-a8b8-8fd6e275a97c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0334adcd-d7d0-589c-8804-ecf0b416ad9b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a41f42d-29bc-5911-b5d7-d52d5cd79dce",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c974e28-8d52-5a49-a0e5-777c2750a7e4",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55c871d8-527b-59e9-bf01-52a9433ae42f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa224928-66b7-58ca-b8c5-b34c8586ff4e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b3260f2-c125-5b83-af58-02df913b0180",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ea1100-5760-5ec7-b3bd-b086f355675c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f0ff472-84f1-500d-86c5-7cc53bb27481",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b92b12ee-95a6-5f71-a10e-b32d7504c6d8",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbbb2100-1b7a-594b-a920-a99aedd840b7",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5acd7017-d532-5f77-8889-724970e93756",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc019fb8-bd9f-5efc-a9e8-6fe14492cb23",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4439f120-370a-5ace-83e6-e5cde760a41d",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b082a582-736f-518c-bf70-2df96d94b462",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25abe957-3b5d-5741-aacd-2d2219ec2388",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.7 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@4.3.30.RELEASE-tuxcare.7"
    }
  ]
}