{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e1f8683c-bd90-54c2-aeba-47957d4a58e8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-beans",
      "version": "5.3.30-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:df518d81-203e-57da-af95-f7df795f72ad",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eeff65f-bdc8-5864-a495-f59d757f9f88",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d653db66-034e-529a-ae62-330f23d6899c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e9f337-8836-5c65-b252-6e4a5bb4320b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7084396b-8f17-572b-98dc-80fbb1173b81",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19891767-eda3-57c5-9474-f92937d9f85b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f52f47f-fd13-5673-871a-be86550305f1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed56adc4-3a8c-55ce-8a4c-41643b6160a3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed6974a3-4270-5e13-853f-5c1b6b5fd46f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd878736-e2f6-572f-a6e3-e583ef97544c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c87578-619e-5e06-9aa3-14f0218a5e6c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82cbd963-c8c7-5f65-a17f-281c45f24716",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d056f828-1de9-5b21-bfb3-d0ef27b219a9",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77aa8551-3e0d-5f21-bba8-1e74fd50d87f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:092196a3-4d3e-5be4-afaf-c553dd0d59b0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25b019a2-0c77-5711-bae7-9681dc723346",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530ed939-7c4f-57e4-a50e-5240e01ee6af",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2584f300-a715-5098-9feb-e47b322993a4",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:276b61b0-0246-5f97-b793-99f336acc951",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a14b9648-82ad-5c2c-a326-5cebd24b2c2c",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd935a1e-e7f4-5348-8d0b-86fc46743de0",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:843f6e02-410d-54ef-ab1f-0404cf8a10cd",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.5 of org.springframework:spring-beans. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0439971f-9147-5995-b3f3-1a4dc5a604c6",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:429e9191-b4af-5fc6-88cd-2e97c6d5ee3a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:963e890f-dca5-53c6-afd2-188390399c92",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245d036d-87be-5540-ba57-9d02cc3bcb9c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d035067e-7936-58c4-872b-9553592fb24f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9810d20-9eb4-5dce-b8c0-9dd3e573e6d5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8f3c7d-fddb-53af-92e1-82a6095653a6",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d56d493-72b1-5c72-87c4-67b945fe51db",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bfb86c5-b4bb-569a-a1de-d4bb25922bf5",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf60dee9-e2db-506a-9b95-e83a9a26c2ad",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1a07637-a491-50cb-8561-1ff80354e289",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abac541b-c932-52f7-a49c-2db307cf8339",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c3c090e-ba5e-5d56-9081-88cd0498493c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb35996-84cb-57cf-a489-dd53abc847bd",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e10c7d-1053-5239-a8f2-adf484ba879c",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa39af2c-1d19-51ed-b9c3-80b1624785d9",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37522e19-55d9-5e39-ac45-d3eb120c80da",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:259e42b0-7566-500e-bdeb-4a54868fd4df",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f11ab55a-d955-5e1b-a41e-d1fa73f238c7",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:309a57cd-fcf5-5531-9569-371d4ae0cf6e",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8530469e-fe8c-5f26-832b-1ce232dc863b",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f5bcd5-8986-5f2f-984f-77eb9a4844b3",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:918baff6-780a-5020-b6e9-4d16565fcd3c",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e977691c-a365-56f7-9725-58e4bcd89430",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a8a2c7-eaa2-565e-842f-12f0a611a473",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2db18833-d405-5906-9ae3-6fdf1985b944",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:967dcfad-668a-581d-beb9-8ddfb47d81d9",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6873b7c-6e78-5cf5-8e47-0430e0817f42",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.30-tuxcare.5 of org.springframework:spring-beans."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-beans@5.3.30-tuxcare.5"
    }
  ]
}