{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e9050eae-5210-597e-a628-65134f5c20bf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "5.3.27-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b55f5712-7855-583e-9526-8b3aa3a437cb",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c44d9b-dd9a-58ed-9f34-887b8f93a458",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f15b5e26-d251-58bd-85c4-ad94da815d0c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0680f8d-e0b9-566f-ba77-dda86c1a9878",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d4b734-cc7d-5ab9-aabc-abeb78fec2b2",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03d7f5e4-3a15-5e99-8719-e864e3fa53b5",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bec7c904-d897-5090-8003-4f416ddf37c0",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386570b1-a801-523f-9e9f-61d99ebf87ef",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:831d9f19-b552-5483-8687-9967fcd71d18",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84df5ed1-3f53-5ce2-91ad-594764a761a6",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a70a2ce-c514-5d95-9969-19090d8df8a5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6f8b8c4-8ce8-5bcf-b855-484760c75401",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-oxm 5.3.27-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83927f63-4660-51fc-8771-ff3a1ca0d4dd",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d0ef806-e303-53c2-a271-83043a93f702",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:131a2ea8-23c5-5983-b850-c8f68f390075",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0138269-34b9-54a9-a2bc-a278f6c369c9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:187a0007-a8b5-507f-944d-973192ad3f4b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76990249-88c3-552e-97bf-1e7d4959a079",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da71c44b-daec-5713-bd05-1336d8acc078",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a0561b-53e9-525c-aba6-65ca1333ed83",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b4508e-86da-554a-8b60-cfbe0799ab58",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84328b98-a79c-5b0e-aedf-cdfabe02506d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58396654-d798-565b-91f9-6c3159b524ab",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-oxm. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a4b6812-ba17-5d72-8748-7bf2d69415a9",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47af1b0f-7f8e-5a99-827b-6f6b89608d5b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754e94af-3320-5280-b1e7-08a0949b1893",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81c00da-f201-5c6e-b794-0cd2f14d248a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5c66932-f787-5286-9c52-0b6f2839a542",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c89b40-e872-53de-b060-753fd68e8983",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:250c75d4-bdd7-531a-99ec-f0571fb68566",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-oxm. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad983907-6390-52dd-801f-7aa1ed47d54e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b39f895c-8d57-5866-aeef-66ba31ead577",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e4f6ce5-b40b-5b18-a2da-33af1a354a7f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c9cf207-c316-56c6-91c5-fde0e1e18c62",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40cdcd55-eb41-5617-976c-fd7e84b26379",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b16eb9e-9bea-5b6d-b1d1-b70de9d28211",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:036ef994-af1e-5652-829b-a68275b14822",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21e9a937-1f9d-55ba-a9ab-aa56c005ab3d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01f1e47f-9ddc-57a3-83a6-417a3582af59",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34510e8e-7d57-59fa-9771-6a05df42dec5",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:905ca151-a9e5-5796-b1c2-67201c14b6ba",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ffbc068-e379-51df-b321-b28f0afd5ee4",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60603208-edd8-5bbf-b623-4068a0db54fc",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7603e02c-e4e5-5314-88cb-23be34e630e4",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b9410d9-5e70-50c0-b715-410d77db52e3",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e06ecd23-c1e5-56db-9325-c2bbb28d1dcd",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4db22a6-e150-520d-b65c-ff21cc522dc6",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:187bc0f8-4f53-5370-bb4e-2c764cb4ece9",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9144c02b-8ee2-541b-bb7b-3249be3530c1",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:691180fa-817d-58c5-8a69-acb49aa6f511",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30ce9438-0ef2-59d5-9204-680d884d144a",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.8 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@5.3.27-tuxcare.8"
    }
  ]
}