{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cce76f15-f249-521c-925c-fe887c892ee8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.30-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9683e2c6-466d-51e4-ad60-4b780e71038e",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f99068-d469-5c82-b0bd-cd921523ed38",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82093e7c-c76a-5681-a101-a9dcb4344e41",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f18abd4-843b-522c-ba87-24cade7d09a1",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cd40889-c78e-5a1f-bf02-8b38e89e93a5",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e9e99ee-2e7e-5c3b-ae1c-0373ec85c07b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51631537-3910-5308-b6c9-fc4663c8bacc",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6206b1c8-6db6-544b-9b50-ebc75648297c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53832a18-3b9e-52a6-afd6-2e89147ab02a",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b301a8e0-c255-5907-a002-29887a4a8ba1",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2166c47-2ee6-5c0a-a770-90823103c505",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8efe8b3f-6a6d-5216-a61e-9de42c981d6e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52ac47c4-6ff3-5d70-a14c-795a67e5a2b8",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ccddc7-ab7b-5f16-8ebb-fd3dadadcf19",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e633ec9e-2b35-51fd-a013-e74f59e2766a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c872c52c-1c04-5dfd-aaf4-2c0c70782893",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13cb748c-2c35-561b-892f-ef0b89f20395",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:facf55c7-fe32-579a-9749-559df2a52712",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49246e53-1bf2-5341-ba92-b3eb85926a7c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:718682e6-54c8-541a-bcbf-dae5053127c8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ee7ff55-2a9b-5622-9bfc-24d800f1817b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5e51324-7907-5713-bad6-2996a77d6462",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc46c52c-ef1e-5b77-891d-1187f79014e2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61dd1c3-76b7-55a6-b530-ec8e5f344aa8",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b49743a-5da7-58ed-b5fd-f086f0caa7e1",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9163b00-a845-595e-ba04-7fd62e52b125",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cee419c-2279-5aad-8ae0-ca197bb7aa5d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a24179-e8ff-5289-86b1-ff2f84593f38",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:951cc650-3f65-5224-8ba4-48f13dd29c3a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bb61b8c-abe9-535a-8ee6-3427f95b3bde",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb8a8204-b033-5469-ab7b-02cf0a9a8014",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:902acb54-314c-5e19-9a7e-e4f01320ba29",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52d45e3-379b-5c23-9846-e5283443a3b4",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:180dcc2b-89da-575c-8da2-6b2a5d838859",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a6d46c-64d1-52ae-8e50-974889c65698",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:729f4495-a9fe-5411-a13c-13bd2a8f84d7",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e8a9f6-c38b-5c02-9725-38f23cb43a44",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1eb75b6-692c-567d-bd73-f7f7a8646a1c",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0405de-9fb5-5c32-b31e-5e316ca048b8",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ffaab0-6ee9-51d7-938b-5744527f7787",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d7f61ba-0c2b-5c63-96bd-50ec7b805c31",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ed52c1-929d-54c1-bd65-e57fc944b191",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a0c81fa-52ae-59e2-873c-cb100914b4c0",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47d57eba-0172-544c-9883-2ed0178e8370",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f3e4e7-2a79-5fca-9141-dcb54fcdff29",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7570e9fe-1ea7-5131-95d2-c6c8f4f7aef0",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b44b8f0-ef3c-594e-8f30-cb4ac7361d1e",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b96bbd9-241c-54bf-b17f-c70a2b462b9d",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1a25ede-fdaa-532f-aec5-91b9710e6c11",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27350b28-7368-5fad-85ca-a293e2c96c65",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.30-tuxcare.7"
    }
  ]
}