{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e654d1de-357e-504e-b7f6-11f6be93adbc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "4.3.4.RELEASE-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6529cdb3-4d4e-5677-91e0-cad0d6c70d73",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c7d7d30-d37e-5e47-9450-7957fea72897",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-9878 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fd3495-6d8d-520a-9893-802b0d5d6243",
      "id": "CVE-2018-11039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-11039 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74236057-ae26-5258-a745-1cd6c550b78a",
      "id": "CVE-2018-11040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-11040 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9b85daf-c4ca-56ac-af3d-f204fbaf40bc",
      "id": "CVE-2018-1199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1199 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:251c6fa9-4a58-5b75-a3e0-c80360424abe",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1257 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15de443b-0c91-556e-aade-58ccf9a7c3af",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1270 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bdce58c-f491-50cd-8ef1-0e1cf07d50ed",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f888b5c-10e8-5964-b2c2-1a6ac32f9a43",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac88f510-9dbb-599c-9226-6c742aef3284",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb31de5-e21a-5849-94b0-3608e18d1311",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282217a1-1814-5005-bd77-dba885150cdf",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b08973dd-7738-5c70-a19d-acf37d3a98dd",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c4a457-2b8c-584a-9fe1-02241b3d0e43",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans. not_affected \u2014 Spring Framework version 4.3.4.RELEASE is not affected by CVE-2021-22118. The vulnerability affects WebFlux multipart file upload handling, but WebFlux does not exist in version 4.3.4.RELEASE. WebFlux was introduced in Spring Framework 5.0, and the vulnerable components (SynchronossPartHttpMessageReader, DefaultPartHttpMessageReader, FileStorage) are not present in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45244691-6cc7-57a4-87a9-68f14ac2364a",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc073395-a49d-5646-a935-38a1683ec36a",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e77a9da-6e9c-5c91-b168-a71c83141098",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2fec94a-0748-562e-b60d-fa3207798463",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba741f9-5d5d-56f4-b24b-d2c0c82a2ca6",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57343d0d-9c00-5444-ace1-7f542b6e2958",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49913b22-c1d8-5cdd-b69d-08ddbec7d039",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d812e92-8ad0-5e4e-a273-e3d22a79f226",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e629f37d-ad9e-52b8-8820-41c2d3cbe628",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690d9887-4062-504a-a181-d9c757b19332",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae86f499-e0b8-5f6e-a623-e78a04de0477",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c3ab677-9344-56fa-81d6-22db8935bc99",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0f8891-a8a5-54b5-8cf6-64afef320406",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans. not_affected \u2014 Target version 4.3.4.RELEASE is not affected by CVE-2024-38820. This vulnerability specifically addresses locale-dependent behavior in String.toLowerCase() calls introduced by the CVE-2022-22968 fix. The target version does not have the CVE-2022-22968 fix, therefore it lacks the vulnerable code pattern (toLowerCase() without Locale.ROOT) that CVE-2024-38820 addresses."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51e9ed61-68e2-59e5-9261-98fc67a4a908",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b25147-0ead-52ef-a58e-82f5d105bce1",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:229d1358-8f86-5f9d-927b-07fe0ceca068",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16b97c91-2e04-5de0-81bb-455ce82b01a5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7fc9d64-eedb-54e0-837d-62a495bea198",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:747d724a-68de-57a3-a9d1-a7ca98fbd4a3",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14047b04-570f-5d1c-9f63-39b9f8737205",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans. not_affected \u2014 Spring Framework 4.3.4.RELEASE is not affected by CVE-2026-22740. This vulnerability is specific to the reactive WebFlux multipart handling introduced in Spring Framework 5.0+, which does not exist in version 4.3.4. The target uses servlet-based synchronous multipart processing with explicit cleanup in finally blocks, a fundamentally different architecture from the reactive stream-based approac..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09fe8976-871b-55b0-ac87-3493032a368b",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89958424-8aa8-55c8-9136-e158b12b277c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e7cac35-8d38-5e01-8857-fd38a2798688",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2de10c68-bd36-594a-a408-66136f60dd76",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48c67c5b-a8ff-5e44-9101-84349b651e41",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c505105-52c8-5577-bc9b-43714abfdd17",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4eb8c87-563e-557b-9ffb-da295157c4e8",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41fd5af2-c74c-5faf-8de4-010c3f170564",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a379ed99-ed7c-5bea-b4db-f844a89b165a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c95448-a552-5680-aaca-89c6e387bcfc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec2b2996-de0d-5dbf-aa8f-2c78942fbb99",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2683604a-c3a4-5ea5-8e81-8b09d252db34",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61f0603d-aa8a-5bc0-b948-44564b5772ed",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81d606e-5b06-519f-bf78-22479aaee49b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f0d30f1-7dc1-536e-b80e-ffef2fe69c5b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans. not_affected \u2014 Spring Framework 4.3.4.RELEASE is NOT affected by CVE-2026-41853. The vulnerability is specific to Spring WebFlux's DefaultServerWebExchange component, which was introduced in Spring Framework 5.0. Version 4.3.4.RELEASE predates WebFlux and uses only the traditional servlet-based Spring MVC architecture. The vulnerable code (DefaultServerWebExchange) does not exist in this version. The upstream..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb88ae9-a4eb-5220-b812-67d8dee924ab",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6af4ed08-6b05-5912-b74e-ad98282ccdc3",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:590edb54-b528-5c51-9cb4-de185624d6c8",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1273b821-7fc8-57ff-993c-0e21e9461bab",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35c228ce-5656-5b25-b656-1795610e6865",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf73e8cc-48c3-5b6c-87af-e53f9255631d",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1fff3b9-db06-5bda-b62a-abbb87470484",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c006cb02-6309-59df-b695-349111d0996e",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7acad901-cd7f-5ee6-80c5-c754b9d0843e",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb366d6b-f2ff-5f12-ac59-fc453b5bfe00",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 4.3.4.RELEASE-tuxcare.4 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@4.3.4.RELEASE-tuxcare.4"
    }
  ]
}