{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1d43486d-6b4b-57f3-9b4a-698932d48463",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webmvc",
      "version": "5.3.31-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a884c493-1e9c-5529-8fab-d6e4936a7108",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70b0f8e4-bae0-5f8a-9a7f-206368984f1a",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2b1489-8d5d-5bd3-a59d-3b2acd0deab3",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:330003a5-6e2d-5ae0-8407-81af17ff0f03",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4393a24-acc8-5e41-8e34-a00a1ff1300e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc5b5a99-1823-55f6-a127-253d9e2d4a29",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91229b07-e865-5967-9eda-d775fce618aa",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d9c3e5-31b4-51d6-902f-a1ea2870c54d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:999be69a-0843-5aa2-9709-a58f70dff185",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79d31e06-087e-590d-abf9-cee7de429f59",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab5cff0-23e6-52cd-a349-465c07f15f2a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6536e1b-bd19-59dd-8e54-9d9f1c5ffdd3",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webmvc 5.3.31-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60e80bb1-b81e-5436-89fd-ab00b07d0723",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e0791d7-c67c-5dc7-9800-8267ad489d51",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17f6aef7-99a3-5726-b927-74eb2b58f232",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5d21c73-a3be-5cb9-a5c9-57d1ffccc84d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f215f05-40d2-5bee-a797-ecfa3a2fcd8e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27d58f48-8831-50d4-b96f-b3b4bbae48d5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7af4bdd3-7442-584c-b789-d6d52ef85b70",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c132a43a-b228-5575-83cf-51521c3a28b8",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d605b864-89d6-5004-8e8c-ee51909383b8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89eeffa7-abc9-5193-bf2a-80bcfda15804",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65d17594-62a9-5489-b5a6-f5926787f0a9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b09c9a0-577b-53fb-b928-9c3c4e7c63df",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de0b104e-43ef-5d53-93f4-6320e0175137",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e721e4b-39ce-509e-8289-c5a1048c7570",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ec2bcb-cd01-57ce-8544-1f789c878c77",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e61e5f-f817-5d66-bc3a-9f3d0f52e062",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01550ca5-8fb8-5cfe-b247-edbdd993e0f7",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:144887d4-7da0-5052-871c-ca7f0eab0f33",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5147a30-ee12-5211-a4a2-90b29131ee89",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c117b36-9f93-5f96-a5e5-9ffab2ec999c",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efd178a3-759a-5f34-bd8e-e20271528dbb",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e53d565-c9d5-5f0e-bfca-3fe34adc4975",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b957432-406a-5b56-8f1c-8156de87a03d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0db75544-9c5d-5525-9c26-d06d08159f07",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2289bbc-fbc0-535e-aedb-f9695b1a0b07",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e078b1aa-3ef9-538d-9702-4d4f5963f4ef",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e48942-cd48-567b-847f-847a9513644c",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a5e0f88-d1c0-5065-9b29-c6aeae89715e",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f34c35c8-fe4c-5691-b274-af47c812f854",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de081eab-fd48-5691-b053-8d3a183816c3",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c40bc9a-8877-58bd-a11d-2368dbacf46e",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef1bd24-6b9a-54d3-b0da-a20c6d326611",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:064b2088-081e-5492-b7f8-1d0e4994d95b",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf1b3279-4a98-5f17-813c-ad56be781cae",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e0a4b4e-1fbf-5451-988f-6cfdabcc37c2",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e2902e5-7171-57ff-bb7a-4799665a6edf",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c36c73f2-b670-5711-a02e-70a1458ccfba",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad7750ad-5cb0-516b-93a9-2650304af354",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bb2fd8-351e-559c-a88a-609cae754cfe",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webmvc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webmvc@5.3.31-tuxcare.12"
    }
  ]
}