{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a80ec673-17fd-521e-b1dc-2c1ad6315acd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.27-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:846d7ada-770b-51b2-a218-c5f3b211ae33",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a35d569-7592-5223-99ea-de3f47896527",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d486c018-5084-52de-9332-c3b23cfa9c1e",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bc46b4d-27e4-5c53-9cd9-b6b33219c823",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a30a5b2-4909-577f-8354-56bb704c8b7a",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6544b715-57af-5cea-b86f-cd439cbfc520",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fac8e690-fad3-5885-9817-114c55046e28",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:024f78c9-c6a3-5da2-aaec-389b6df079d1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0576ba6b-0e8a-51f8-a464-a645b174d2b2",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc53344-301d-52ee-9dfa-c014487a316b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb49e79-33fb-53bc-be5d-d486515fde61",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52c2d84c-4cac-57c0-aa19-e4b7b5ed304b",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-beans 5.3.27-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abc83b0c-af1e-5fcb-a773-515d4840797e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48a62f5d-76fa-59e5-baf7-40545269c423",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0a36255-c2e8-53cd-b466-77693dd1e65c",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e8e417-336e-5fe8-869e-af0128441765",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:affc73ec-11a2-5f9c-b1e7-03edcb874219",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48535f2b-8a99-5db4-9e6d-3a033c13ff02",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba01b84a-1039-50ef-95b8-092fcb309237",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:911cc76a-bc38-563c-b418-4c58b541e24d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31019b4b-ab32-5458-8fc5-3aff8a1a106f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81cb4156-f937-573e-872b-7b78b8890c0f",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a41b9a0c-dcb8-5d19-a778-16848d4cc81a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-beans. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea6d502-2c9f-52b8-ab32-7ff0e71d1e29",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b0f5c2-e207-5b00-a45b-34e4b8f644b1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75abc757-752e-5792-aa8c-1d05d79206c1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ded402-27d1-588c-9f8f-5c0de9af969f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9b44bb6-7ac4-5a27-ad86-9c60288d6a91",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6df6e8-1487-53dc-a964-54afba6b464c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d1bb5d4-b973-5b33-8800-7840f97a71cc",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-beans. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:009df243-b3e0-590f-8a41-c75e41ab01dc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:add201cb-732a-5dfe-9364-faf70d7f7fca",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b676e4-f4ea-5773-90b8-62e6567a50e1",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14d7cb6d-a8ba-54b3-bd9e-95c655a70135",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3425cfdb-5b08-50cd-a709-54c23daec330",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a951e8cf-83be-5221-9732-c2968709063f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feece112-9968-5b36-b402-5a137fb5b8f4",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ec26d6-15e3-53c9-b497-d8621dc574cf",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a284f074-2964-53af-adea-7aeac65c0739",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f53d1fa-5625-57f3-8b0b-97c381bd2a0f",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a37b93b5-c41e-538c-ace0-8ce8856c213f",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cb3e515-2bab-55cb-9fc4-68942b752af7",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:699e410c-b93f-539f-8ca2-5e5bf79c902f",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83df3d26-8782-5299-9505-1809fce82b37",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ebccb0-b864-5f30-bf22-71ce5c5cab40",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6e7e9e8-e6a5-5eda-8fcc-59049e822b8d",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b70c1cb1-313e-5ef7-bd90-216c1a6f03c8",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34fef752-1323-547d-b302-875aef6286b3",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beca2f94-d8bb-55f6-95c7-4713d2773c18",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:729f2663-30ef-5d97-a893-6ef4e8ced5fb",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e5ce2e1-91b0-54de-8d0c-d1870fd0ca2b",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.8 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.27-tuxcare.8"
    }
  ]
}