{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:24f77f34-05b2-55f0-877f-34f8e97e1f2c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jcl",
      "version": "5.3.30-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2e9da218-af46-5b53-bd89-3ef92cd341f4",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd825e29-b676-560c-a05f-03a9816603c1",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bed6f48-cf58-5ec2-9705-6e075088434c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1387b33e-eaef-5b7d-85a6-e17933db10f1",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245fb5a3-e97b-5082-9513-b3b8bc0d6af9",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46eb0b07-57b3-54a1-9d3e-adc7a4eb6216",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9c6e9ec-9ecf-56f8-acfa-f6f5602a2df3",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18a667eb-6ba3-5fc2-84fb-e729e1416bfe",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30bbe243-691c-5c72-aff9-8156d559b4ac",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8608ec64-d3e0-52b6-be63-a94511976e67",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc4f9326-7a8c-5b9f-b59d-c03007b44e98",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14dfb6e3-7585-5307-ae8b-749d69146359",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8b8e7ed-d538-592e-a0b9-436db0b9a2de",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc073e42-5f9e-5ced-b4b7-a3266fca8a8b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c065b5-de9a-53fe-af7a-24bca9fe3460",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3be726dd-5464-5719-b9b7-f4313aa15ea6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afe6d51a-b2bc-5ad2-90a9-027ae5e60906",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a88104-a5a6-5d24-9ae2-ee59117bec03",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2746fa44-8f63-5073-a989-e6defff761ec",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37465bb8-a82f-5ce4-9b50-10d2f64b668d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16fd162f-6659-5c34-854b-e4aef824390a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0709ff49-fc19-5494-8ac0-e2b397f6817a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.8 of org.springframework:spring-jcl. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6e2597e-4fb4-5d19-88a1-95449fb3c45d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07b57447-d961-54eb-9ac0-b09ad072a809",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b1dd42-6f54-5498-bba6-ced466407dc4",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f039ab15-b0d5-5288-9856-a8465ed104d1",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bedba52-04da-5be3-a0dd-3900f91d6bad",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:713689c1-b538-53ae-bae0-0df8d1f8297e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83ade686-5858-5412-a924-5bfaab3a879e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2111a419-08fe-5727-aa60-1256df005ba4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:466b4a65-6160-57ad-adc0-7e8b034e52af",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:048303fe-6730-59d0-a9d2-b11698feec72",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2611e22f-3185-5f5d-9e82-075d93fbb311",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eed247cf-4d3e-5a02-9884-b5dfb85cf302",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca696d89-4a9a-5b79-9c4d-73d73c8761e5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:474ef01b-ad8d-5244-8376-f0aabc8dd40a",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b9d759-f7b6-59c3-942b-b36344b2eb85",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc1b0064-52b7-5daa-aa23-1d6602b647d5",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b5ba94e-dce1-5503-94ca-72f077477f45",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9568b2-38f9-5cfb-be92-d2014677390a",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed06f9af-e119-5a4d-8cd8-9fa3dc47b879",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf4b3035-12a4-5328-bfea-c3ae956af553",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa444406-4c9a-5dd2-9f48-b7ef00d57ef3",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9349a6-ce69-52c4-8d8a-9f21cedeb4a4",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b77050d6-0347-562c-9ee2-4029e2c906a4",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a41806-2042-5aba-a749-08685bf7d008",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b77b79-89a8-5793-9898-5a4f2d29f5e6",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98e38db-2551-59ee-8a28-86ebb6af3720",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d2b409f-9fee-5aee-8ca2-428a8ff03bf6",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2820be46-4547-54c9-a7a2-4fd7b0812b0b",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.30-tuxcare.8 of org.springframework:spring-jcl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jcl@5.3.30-tuxcare.8"
    }
  ]
}