{
  "bomFormat" : "CycloneDX",
  "specVersion" : "1.6",
  "serialNumber" : "urn:uuid:9de64f12-10a5-33d7-b37d-d72682e9cbe3",
  "version" : 1,
  "metadata" : {
    "timestamp" : "2026-09-01T07:42:04Z",
    "authors" : [ {
      "name" : "Moderne Backpatch Alliance",
      "email" : "support@moderne.io"
    } ],
    "component" : {
      "type" : "application",
      "name" : "osera-backpatch-catalog",
      "version" : "2026-09-01"
    }
  },
  "components" : [ {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.activemq/activemq-broker@5.14.5%2Bbackpatch.001",
    "group" : "org.apache.activemq",
    "name" : "activemq-broker",
    "version" : "5.14.5+backpatch.001",
    "purl" : "pkg:maven/org.apache.activemq/activemq-broker@5.14.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-46604 onto the 5.14.5 baseline.",
      "commits" : [ {
        "uid" : "3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b",
        "url" : "https://github.com/apache/activemq/commit/3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.activemq/activemq-client@5.14.5%2Bbackpatch.001",
    "group" : "org.apache.activemq",
    "name" : "activemq-client",
    "version" : "5.14.5+backpatch.001",
    "purl" : "pkg:maven/org.apache.activemq/activemq-client@5.14.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-46604 onto the 5.14.5 baseline.",
      "commits" : [ {
        "uid" : "3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b",
        "url" : "https://github.com/apache/activemq/commit/3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.activemq/activemq-openwire-legacy@5.14.5%2Bbackpatch.001",
    "group" : "org.apache.activemq",
    "name" : "activemq-openwire-legacy",
    "version" : "5.14.5+backpatch.001",
    "purl" : "pkg:maven/org.apache.activemq/activemq-openwire-legacy@5.14.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-46604 onto the 5.14.5 baseline.",
      "commits" : [ {
        "uid" : "3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b",
        "url" : "https://github.com/apache/activemq/commit/3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.activemq/artemis-server@2.44.0%2Bbackpatch.001",
    "group" : "org.apache.activemq",
    "name" : "artemis-server",
    "version" : "2.44.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.activemq/artemis-server@2.44.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c731fb739cba9879859083820e7781b5a18bd116909fb6f03cd31fb2c40806ff"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-27446 onto the 2.44.0 baseline.",
      "commits" : [ {
        "uid" : "521e672e4108675806d748158444ce23f9ef76ca",
        "url" : "https://github.com/apache/activemq-artemis/commit/521e672e4108675806d748158444ce23f9ef76ca"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.avro/avro@1.11.3%2Bbackpatch.001",
    "group" : "org.apache.avro",
    "name" : "avro",
    "version" : "1.11.3+backpatch.001",
    "purl" : "pkg:maven/org.apache.avro/avro@1.11.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8ba799f4e9fd0da9d9c5acc6f510c7d72cf2933902238da8fdd444e6b0bd67fb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-47561 onto the 1.11.3 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
    "group" : "org.bouncycastle",
    "name" : "bcprov-jdk15on",
    "version" : "1.47+backpatch.001",
    "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-1000338, CVE-2016-1000341, CVE-2016-1000342, CVE-2016-1000343, CVE-2016-1000344, CVE-2016-1000352, CVE-2020-26939 onto the 1.47 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
    "group" : "org.bouncycastle",
    "name" : "bcprov-jdk15on",
    "version" : "1.47+backpatch.002",
    "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-1000338, CVE-2016-1000341, CVE-2016-1000342, CVE-2020-26939 onto the 1.47 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001",
    "group" : "org.bouncycastle",
    "name" : "bcprov-jdk15",
    "version" : "1.46+backpatch.001",
    "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "efb97aa5fae48e0f4ca2b3f66154f1973d1d63ce10c19adef838be6738fec3b1"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-1000338, CVE-2016-1000342 onto the 1.46 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.mchange/c3p0@0.9.5.2%2Bbackpatch.001",
    "group" : "com.mchange",
    "name" : "c3p0",
    "version" : "0.9.5.2+backpatch.001",
    "purl" : "pkg:maven/com.mchange/c3p0@0.9.5.2%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2018-20433 onto the 0.9.5.2 baseline.",
      "commits" : [ {
        "uid" : "7dfdda63f42759a5ec9b63d725b7412f74adb3e1",
        "url" : "https://github.com/swaldman/c3p0/commit/7dfdda63f42759a5ec9b63d725b7412f74adb3e1"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.calcite/calcite-core@1.29.0%2Bbackpatch.001",
    "group" : "org.apache.calcite",
    "name" : "calcite-core",
    "version" : "1.29.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.calcite/calcite-core@1.29.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ac01cfa3c03efe086a07231602df225cf220f7cb461a349b6b34a8d57b4e6bb6"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-39135 onto the 1.29.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.calcite/calcite-core@1.30.0%2Bbackpatch.001",
    "group" : "org.apache.calcite",
    "name" : "calcite-core",
    "version" : "1.30.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.calcite/calcite-core@1.30.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ad6b346076f5e04229106d216682d8e5118c0e2577a06a30344c928e8a9c2406"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-39135 onto the 1.30.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.calcite/calcite-core@1.31.0%2Bbackpatch.001",
    "group" : "org.apache.calcite",
    "name" : "calcite-core",
    "version" : "1.31.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.calcite/calcite-core@1.31.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "35af7482674a968e0c5dfbb0a826722c342fe181cecf654a64005614271172dc"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-39135 onto the 1.31.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.001",
    "group" : "org.apache.camel",
    "name" : "camel-core",
    "version" : "2.25.4+backpatch.001",
    "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-11971 onto the 2.25.4 baseline.",
      "commits" : [ {
        "uid" : "b954402272ddcfbb45dc1495520f920e70cc041c",
        "url" : "https://github.com/apache/camel/commit/b954402272ddcfbb45dc1495520f920e70cc041c"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.002",
    "group" : "org.apache.camel",
    "name" : "camel-core",
    "version" : "2.25.4+backpatch.002",
    "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-11971 onto the 2.25.4 baseline.",
      "commits" : [ {
        "uid" : "b954402272ddcfbb45dc1495520f920e70cc041c",
        "url" : "https://github.com/apache/camel/commit/b954402272ddcfbb45dc1495520f920e70cc041c"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.003",
    "group" : "org.apache.camel",
    "name" : "camel-core",
    "version" : "2.25.4+backpatch.003",
    "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.003",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-11971 onto the 2.25.4 baseline.",
      "commits" : [ {
        "uid" : "b954402272ddcfbb45dc1495520f920e70cc041c",
        "url" : "https://github.com/apache/camel/commit/b954402272ddcfbb45dc1495520f920e70cc041c"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.004",
    "group" : "org.apache.camel",
    "name" : "camel-core",
    "version" : "2.25.4+backpatch.004",
    "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.004",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-11971 onto the 2.25.4 baseline.",
      "commits" : [ {
        "uid" : "b954402272ddcfbb45dc1495520f920e70cc041c",
        "url" : "https://github.com/apache/camel/commit/b954402272ddcfbb45dc1495520f920e70cc041c"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.4%2Bbackpatch.001",
    "group" : "commons-beanutils",
    "name" : "commons-beanutils",
    "version" : "1.9.4+backpatch.001",
    "purl" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c318dcfb461e10d5cb8b478f9e26cb3138c94b9a5e94c312312a79187bbd933a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-48734 onto the 1.9.4 baseline.",
      "commits" : [ {
        "uid" : "28ad955a1613ed5885870cc7da52093c1ce739dc",
        "url" : "https://github.com/apache/commons-beanutils/commit/28ad955a1613ed5885870cc7da52093c1ce739dc"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001",
    "group" : "commons-beanutils",
    "name" : "commons-beanutils",
    "version" : "1.9.2+backpatch.001",
    "purl" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "aef18ccc3f0b2f291ba102c691785c86b1c9ad233382739fe0eb2e0553677d25"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2014-0114, CVE-2019-10086 onto the 1.9.2 baseline.",
      "commits" : [ {
        "uid" : "62e82ad92cf4818709d6044aaf257b73d42659a4",
        "url" : "https://github.com/apache/commons-beanutils/commit/62e82ad92cf4818709d6044aaf257b73d42659a4"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001",
    "group" : "commons-collections",
    "name" : "commons-collections",
    "version" : "3.2.1+backpatch.001",
    "purl" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "25a66f3767667b8c18cc46db0213d3c6fe60afa75001561f1d139a1a56595fcd"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2015-7501, CVE-2015-6420 onto the 3.2.1 baseline.",
      "commits" : [ {
        "uid" : "1642b00d67b96de87cad44223efb9ab5b4fb7be5",
        "url" : "https://github.com/apache/commons-collections/commit/1642b00d67b96de87cad44223efb9ab5b4fb7be5"
      }, {
        "uid" : "bce4d022f27a723fa0e0b7484dcbf0afa2dd210a",
        "url" : "https://github.com/apache/commons-collections/commit/bce4d022f27a723fa0e0b7484dcbf0afa2dd210a"
      }, {
        "uid" : "5ec476b0b756852db865b2e442180f091f8209ee",
        "url" : "https://github.com/apache/commons-collections/commit/5ec476b0b756852db865b2e442180f091f8209ee"
      }, {
        "uid" : "d9a00134f16d685bea11b2b12de824845e6473e3",
        "url" : "https://github.com/apache/commons-collections/commit/d9a00134f16d685bea11b2b12de824845e6473e3"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001",
    "group" : "org.apache.commons",
    "name" : "commons-collections4",
    "version" : "4.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3445b9c4342d8e1a6746957390372ab5cbc6eed7d838d6c733a70fcb3c604af5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2015-7501, CVE-2015-6420 onto the 4.0 baseline.",
      "commits" : [ {
        "uid" : "e585cd0433ae4cfbc56e58572b9869bd0c86b611",
        "url" : "https://github.com/apache/commons-collections/commit/e585cd0433ae4cfbc56e58572b9869bd0c86b611"
      }, {
        "uid" : "bce4d022f27a723fa0e0b7484dcbf0afa2dd210a",
        "url" : "https://github.com/apache/commons-collections/commit/bce4d022f27a723fa0e0b7484dcbf0afa2dd210a"
      }, {
        "uid" : "d9a00134f16d685bea11b2b12de824845e6473e3",
        "url" : "https://github.com/apache/commons-collections/commit/d9a00134f16d685bea11b2b12de824845e6473e3"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001",
    "group" : "org.apache.commons",
    "name" : "commons-compress",
    "version" : "1.20+backpatch.001",
    "purl" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "71e8a3e592d853c7c7bdb64536e25b51dca38f6a131c2210767abf966c84e1be"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 onto the 1.20 baseline.",
      "commits" : [ {
        "uid" : "3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321",
        "url" : "https://github.com/apache/commons-compress/commit/3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321"
      }, {
        "uid" : "5761493cbaf7a7d608a3b68f4d61aaa822dbeb4f",
        "url" : "https://github.com/apache/commons-compress/commit/5761493cbaf7a7d608a3b68f4d61aaa822dbeb4f"
      }, {
        "uid" : "41359f56e62d41ed59493cdcbaa5d52d0f89fbb9",
        "url" : "https://github.com/apache/commons-compress/commit/41359f56e62d41ed59493cdcbaa5d52d0f89fbb9"
      }, {
        "uid" : "5c5f8a89e91b95c0ba984549b5804289f55b8200",
        "url" : "https://github.com/apache/commons-compress/commit/5c5f8a89e91b95c0ba984549b5804289f55b8200"
      }, {
        "uid" : "004e87375572d459ff51c19fe35aa83685cc0cd0",
        "url" : "https://github.com/apache/commons-compress/commit/004e87375572d459ff51c19fe35aa83685cc0cd0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001",
    "group" : "org.apache.commons",
    "name" : "commons-configuration2",
    "version" : "2.5+backpatch.001",
    "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "73326034b78811ab5938916b3c01961f1d8a6d16f6cc3d252b1bf78fe06bebea"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-1953, CVE-2022-33980 onto the 2.5 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.7%2Bbackpatch.001",
    "group" : "org.apache.commons",
    "name" : "commons-configuration2",
    "version" : "2.7+backpatch.001",
    "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "9f4bd7bf785e4dbcf5ee33b059468a5cd4576a733c18643371c45be0833b63ef"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-33980 onto the 2.7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001",
    "group" : "org.apache.commons",
    "name" : "commons-configuration2",
    "version" : "2.6+backpatch.001",
    "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8ff1c4eccef6b54c4e484ccf5ff9bc27f4c339ed1f1c28c284568398758d84de"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-1953, CVE-2022-33980 onto the 2.6 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001",
    "group" : "commons-fileupload",
    "name" : "commons-fileupload",
    "version" : "1.3.1+backpatch.001",
    "purl" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "45f894e8ad8d4073d36d6cbcadaccd43bc62646cddedcaab845503ae1dd66023"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-1000031, CVE-2016-3092, CVE-2023-24998 onto the 1.3.1 baseline.",
      "commits" : [ {
        "uid" : "d7a7b613373789fa6c3015457f1a15c7c5efd84d",
        "url" : "https://github.com/apache/commons-fileupload/commit/d7a7b613373789fa6c3015457f1a15c7c5efd84d"
      }, {
        "uid" : "388e824518697c2c8f9f83fd964621d9c2f8fc4c",
        "url" : "https://github.com/apache/commons-fileupload/commit/388e824518697c2c8f9f83fd964621d9c2f8fc4c"
      }, {
        "uid" : "e20c04990f7420ca917e96a84cec58b13a1b3d17",
        "url" : "https://github.com/apache/commons-fileupload/commit/e20c04990f7420ca917e96a84cec58b13a1b3d17"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-httpclient/commons-httpclient@3.1%2Bbackpatch.001",
    "group" : "commons-httpclient",
    "name" : "commons-httpclient",
    "version" : "3.1+backpatch.001",
    "purl" : "pkg:maven/commons-httpclient/commons-httpclient@3.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4907385ea2fc94558a975b1a460423d9356c45a08e1262863f1ea82bfa237117"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2012-5783 onto the 3.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.0.1+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "adf90d86851cd5d25c362ef0d0c313fb929cf785f6a19301762f531995eb50a8"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.0.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.1+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b87caae4d0a82c42d51467c54d824f43bde7350cd690e9ed9a9fbb13aab7bfc9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.2+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1743bad71fc0f8459ff1d7fbc47bc430b0db17359b86539c659170e0d176a730"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.2 baseline.",
      "commits" : [ {
        "uid" : "2736b6fe0b3fa22ec8e2b4184897ecadb021fc78",
        "url" : "https://github.com/apache/commons-io/commit/2736b6fe0b3fa22ec8e2b4184897ecadb021fc78"
      }, {
        "uid" : "rel/commons-io-2.14.0",
        "url" : "https://github.com/apache/commons-io/commit/rel/commons-io-2.14.0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.3+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "92a82c53d0b34a391b9fe9ce2a13165592be0472fdcce15c2e7b55e8771d11e3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.3 baseline.",
      "commits" : [ {
        "uid" : "2736b6fe0b3fa22ec8e2b4184897ecadb021fc78",
        "url" : "https://github.com/apache/commons-io/commit/2736b6fe0b3fa22ec8e2b4184897ecadb021fc78"
      }, {
        "uid" : "rel/commons-io-2.14.0",
        "url" : "https://github.com/apache/commons-io/commit/rel/commons-io-2.14.0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.4+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "cb038938ca50a852ab61810743ab595c760a77271dcf1db248251a0dd773b067"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.4 baseline.",
      "commits" : [ {
        "uid" : "2736b6fe0b3fa22ec8e2b4184897ecadb021fc78",
        "url" : "https://github.com/apache/commons-io/commit/2736b6fe0b3fa22ec8e2b4184897ecadb021fc78"
      }, {
        "uid" : "rel/commons-io-2.14.0",
        "url" : "https://github.com/apache/commons-io/commit/rel/commons-io-2.14.0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.5+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b9e75b780f1b09a439ed496828cccdccfbb4f89b98d8cc898b4891b642657d33"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.5 baseline.",
      "commits" : [ {
        "uid" : "2736b6fe0b3fa22ec8e2b4184897ecadb021fc78",
        "url" : "https://github.com/apache/commons-io/commit/2736b6fe0b3fa22ec8e2b4184897ecadb021fc78"
      }, {
        "uid" : "rel/commons-io-2.14.0",
        "url" : "https://github.com/apache/commons-io/commit/rel/commons-io-2.14.0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.6+backpatch.001",
    "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "fde9ae5437a654d54cc12c36bc6cb364bb9488cbfe44560f0c28f72ace06d07f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554 onto the 2.6 baseline.",
      "commits" : [ {
        "uid" : "2736b6fe0b3fa22ec8e2b4184897ecadb021fc78",
        "url" : "https://github.com/apache/commons-io/commit/2736b6fe0b3fa22ec8e2b4184897ecadb021fc78"
      }, {
        "uid" : "06fde31494c279ad940149e1a3d4944040c73c0d",
        "url" : "https://github.com/apache/commons-io/commit/06fde31494c279ad940149e1a3d4944040c73c0d"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002",
    "group" : "commons-io",
    "name" : "commons-io",
    "version" : "2.6+backpatch.002",
    "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c68a5fc84231e0374e9e45bcd20c494680c27da61b7bce907245de17289be810"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-29425, CVE-2024-47554, XRAY-125253 onto the 2.6 baseline.",
      "commits" : [ {
        "uid" : "2736b6fe0b3fa22ec8e2b4184897ecadb021fc78",
        "url" : "https://github.com/apache/commons-io/commit/2736b6fe0b3fa22ec8e2b4184897ecadb021fc78"
      }, {
        "uid" : "06fde31494c279ad940149e1a3d4944040c73c0d",
        "url" : "https://github.com/apache/commons-io/commit/06fde31494c279ad940149e1a3d4944040c73c0d"
      }, {
        "uid" : "97ae01c95837f50a2e9be34c370b271c4d8fc88b",
        "url" : "https://github.com/apache/commons-io/commit/97ae01c95837f50a2e9be34c370b271c4d8fc88b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/commons-lang/commons-lang@2.6%2Bbackpatch.001",
    "group" : "commons-lang",
    "name" : "commons-lang",
    "version" : "2.6+backpatch.001",
    "purl" : "pkg:maven/commons-lang/commons-lang@2.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e2bbb0e81b016063470a39362a691fe658092270555b38de984e03d65afae311"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-48924 onto the 2.6 baseline.",
      "commits" : [ {
        "uid" : "b424803abdb2bec818e4fbcb251ce031c22aca53",
        "url" : "https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.commons/commons-text@1.9%2Bbackpatch.001",
    "group" : "org.apache.commons",
    "name" : "commons-text",
    "version" : "1.9+backpatch.001",
    "purl" : "pkg:maven/org.apache.commons/commons-text@1.9%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "988463b04593b2ae8d4690ca4206eeb0478f53892401460014a7300be000c539"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-42889 onto the 1.9 baseline.",
      "commits" : [ {
        "uid" : "b9b40b903e2d1f9935039803c9852439576780ea",
        "url" : "https://github.com/apache/commons-text/commit/b9b40b903e2d1f9935039803c9852439576780ea"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001",
    "group" : "org.apache.cxf",
    "name" : "cxf-core",
    "version" : "3.3.13+backpatch.001",
    "purl" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b278f3384a529395d67ea9732afdc0c6c656af92131db59399c42f3fbda828b7"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-46364, CVE-2022-46363 onto the 3.3.13 baseline.",
      "commits" : [ {
        "uid" : "bff4eb1959ecac3ddd5e824550497ef137479e26",
        "url" : "https://github.com/apache/cxf/commit/bff4eb1959ecac3ddd5e824550497ef137479e26"
      }, {
        "uid" : "a1b5578cf9175f27793a7fc0a9070f92aab5d2d5",
        "url" : "https://github.com/apache/cxf/commit/a1b5578cf9175f27793a7fc0a9070f92aab5d2d5"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001",
    "group" : "org.apache.cxf",
    "name" : "cxf-rt-transports-http",
    "version" : "3.3.13+backpatch.001",
    "purl" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e3644a5faae2168dd5f4f86fe3966ec71065cf3c79acf2a071b92ab1d7268766"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-46364, CVE-2022-46363 onto the 3.3.13 baseline.",
      "commits" : [ {
        "uid" : "bff4eb1959ecac3ddd5e824550497ef137479e26",
        "url" : "https://github.com/apache/cxf/commit/bff4eb1959ecac3ddd5e824550497ef137479e26"
      }, {
        "uid" : "a1b5578cf9175f27793a7fc0a9070f92aab5d2d5",
        "url" : "https://github.com/apache/cxf/commit/a1b5578cf9175f27793a7fc0a9070f92aab5d2d5"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.cxf/cxf-core@3.5.11%2Bbackpatch.001",
    "group" : "org.apache.cxf",
    "name" : "cxf-core",
    "version" : "3.5.11+backpatch.001",
    "purl" : "pkg:maven/org.apache.cxf/cxf-core@3.5.11%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-48913 onto the 3.5.11 baseline.",
      "commits" : [ {
        "uid" : "b22a80b341bf7e24d2df6cb95a6e01e78d3ff7aa",
        "url" : "https://github.com/apache/cxf/commit/b22a80b341bf7e24d2df6cb95a6e01e78d3ff7aa"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.cxf/cxf-rt-transports-jms@3.5.11%2Bbackpatch.001",
    "group" : "org.apache.cxf",
    "name" : "cxf-rt-transports-jms",
    "version" : "3.5.11+backpatch.001",
    "purl" : "pkg:maven/org.apache.cxf/cxf-rt-transports-jms@3.5.11%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-48913 onto the 3.5.11 baseline.",
      "commits" : [ {
        "uid" : "b22a80b341bf7e24d2df6cb95a6e01e78d3ff7aa",
        "url" : "https://github.com/apache/cxf/commit/b22a80b341bf7e24d2df6cb95a6e01e78d3ff7aa"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/dom4j/dom4j@1.6.1%2Bbackpatch.001",
    "group" : "dom4j",
    "name" : "dom4j",
    "version" : "1.6.1+backpatch.001",
    "purl" : "pkg:maven/dom4j/dom4j@1.6.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-10683 onto the 1.6.1 baseline.",
      "commits" : [ {
        "uid" : "a8228522a99a02146106672a34c104adbda5c658",
        "url" : "https://github.com/dom4j/dom4j/commit/a8228522a99a02146106672a34c104adbda5c658"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.owasp.esapi/esapi@2.2.3.1%2Bbackpatch.001",
    "group" : "org.owasp.esapi",
    "name" : "esapi",
    "version" : "2.2.3.1+backpatch.001",
    "purl" : "pkg:maven/org.owasp.esapi/esapi@2.2.3.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "53eb34020410b0050d0ed0ce5e11969fd5235644008334f658e684cad75b1856"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-23457 onto the 2.2.3.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.001",
    "group" : "com.alibaba",
    "name" : "fastjson",
    "version" : "1.2.68+backpatch.001",
    "purl" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "5ec4805437cb95737bf6bbf73fbaaebb91334f9695aa07464211eb0dd528a75a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25845 onto the 1.2.68 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.002",
    "group" : "com.alibaba",
    "name" : "fastjson",
    "version" : "1.2.68+backpatch.002",
    "purl" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1ee09de4e801eb064a971c5f30fa74e5928980f66b5ac1110c353cdf6f1e16a3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25845 onto the 1.2.68 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.graphql-java/graphql-java@18.7%2Bbackpatch.001",
    "group" : "com.graphql-java",
    "name" : "graphql-java",
    "version" : "18.7+backpatch.001",
    "purl" : "pkg:maven/com.graphql-java/graphql-java@18.7%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-40094 onto the 18.7 baseline.",
      "commits" : [ {
        "uid" : "97743bc1b5caa2b0bd894dc8e128b47e4d771e4a",
        "url" : "https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a"
      }, {
        "uid" : "592ec17d20f7b307bf10fdab26868da1445cde76",
        "url" : "https://github.com/graphql-java/graphql-java/commit/592ec17d20f7b307bf10fdab26868da1445cde76"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.code.gson/gson@2.8.8%2Bbackpatch.001",
    "group" : "com.google.code.gson",
    "name" : "gson",
    "version" : "2.8.8+backpatch.001",
    "purl" : "pkg:maven/com.google.code.gson/gson@2.8.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "2575baa2fd678a378998e9c3f238d68bdffe327303c00192401eff3ee570be17"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25647 onto the 2.8.8 baseline.",
      "commits" : [ {
        "uid" : "4906461db7dff60889ead0c03b84b3fc6aea150a",
        "url" : "https://github.com/google/gson/commit/4906461db7dff60889ead0c03b84b3fc6aea150a"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001",
    "group" : "com.google.guava",
    "name" : "guava",
    "version" : "20.0+backpatch.001",
    "purl" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4bf902166aadcdb40f8cd44b3d022b288af2d89c4adae3a884f560d604bb6523"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2018-10237, CVE-2023-2976, CVE-2020-8908 onto the 20.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001",
    "group" : "com.google.guava",
    "name" : "guava",
    "version" : "31.1-jre+backpatch.001",
    "purl" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c67a840999b3e5d99dc3f5fd428e8041aee3ed9f3f79274203ecada96aaef456"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-2976, CVE-2020-8908 onto the 31.1-jre baseline.",
      "commits" : [ {
        "uid" : "fdbf77d3f2b826fc0a70b1f9b9994b140ddf3bd8",
        "url" : "https://github.com/google/guava/commit/fdbf77d3f2b826fc0a70b1f9b9994b140ddf3bd8"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.001",
    "group" : "com.h2database",
    "name" : "h2",
    "version" : "1.4.200+backpatch.001",
    "purl" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-42392 onto the 1.4.200 baseline.",
      "commits" : [ {
        "uid" : "956c6241868332c5b440f5d55ea8fdc1e51ae4fd",
        "url" : "https://github.com/h2database/h2database/commit/956c6241868332c5b440f5d55ea8fdc1e51ae4fd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002",
    "group" : "com.h2database",
    "name" : "h2",
    "version" : "1.4.200+backpatch.002",
    "purl" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-42392, CVE-2021-23463 onto the 1.4.200 baseline.",
      "commits" : [ {
        "uid" : "956c6241868332c5b440f5d55ea8fdc1e51ae4fd",
        "url" : "https://github.com/h2database/h2database/commit/956c6241868332c5b440f5d55ea8fdc1e51ae4fd"
      }, {
        "uid" : "d83285fd2e48fb075780ee95badee6f5a15ea7f8",
        "url" : "https://github.com/h2database/h2database/commit/d83285fd2e48fb075780ee95badee6f5a15ea7f8"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.001",
    "group" : "org.apache.hadoop",
    "name" : "hadoop-common",
    "version" : "2.7.7+backpatch.001",
    "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "bdd9b21f11f0d71f15f8e633ccc76c56bb520cef44d56e94aa65903fc39316ba"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25168 onto the 2.7.7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.002",
    "group" : "org.apache.hadoop",
    "name" : "hadoop-common",
    "version" : "2.7.7+backpatch.002",
    "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4ee74fda4d9da19746c2e78c5bb3fdab55825f8ff17faf267166f44097c182e7"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25168 onto the 2.7.7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.003",
    "group" : "org.apache.hadoop",
    "name" : "hadoop-common",
    "version" : "2.7.7+backpatch.003",
    "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.003",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e89de6e44a5699fb8a2c1a98d638734f3f183906b0df540c1ce2d31b0fbe32d6"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25168 onto the 2.7.7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.004",
    "group" : "org.apache.hadoop",
    "name" : "hadoop-common",
    "version" : "2.7.7+backpatch.004",
    "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.004",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1842bf7b517b4bc52c6c4c9f0bb8a11431e39950381720dc510b54f52556e1b8"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25168 onto the 2.7.7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.001",
    "group" : "org.apache.hadoop",
    "name" : "hadoop-common",
    "version" : "2.8.5+backpatch.001",
    "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "27dbd447221707562f852d090b16eea17d005d7f562c8de9f09e314aae296271"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25168 onto the 2.8.5 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.002",
    "group" : "org.apache.hadoop",
    "name" : "hadoop-common",
    "version" : "2.8.5+backpatch.002",
    "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e1450d47f3ed794e488da9d25ebaaf9a42d6ed84cb089e2cb9e8b875e4bc4f42"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-25168 onto the 2.8.5 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.001",
    "group" : "com.hazelcast",
    "name" : "hazelcast",
    "version" : "3.10.6+backpatch.001",
    "purl" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b85653ca4eef794f5b534fa8ab441dd16bf0fad3780e59958b5c92c1e50d05a4"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-10750 onto the 3.10.6 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.002",
    "group" : "com.hazelcast",
    "name" : "hazelcast",
    "version" : "3.10.6+backpatch.002",
    "purl" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f2fe95e49993b774cbd0264904a31bfffedfd91bcd42ad15af776975b02613f5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-10750 onto the 3.10.6 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.hibernate/hibernate-core@5.4.33.Final%2Bbackpatch.001",
    "group" : "org.hibernate",
    "name" : "hibernate-core",
    "version" : "5.4.33.Final+backpatch.001",
    "purl" : "pkg:maven/org.hibernate/hibernate-core@5.4.33.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "36b2e297a66a4168494257765b6e0f64955c8a5d09b6ee17510312548f06bd25"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-0603 onto the 5.4.33.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.hibernate/hibernate-core@5.5.9.Final%2Bbackpatch.001",
    "group" : "org.hibernate",
    "name" : "hibernate-core",
    "version" : "5.5.9.Final+backpatch.001",
    "purl" : "pkg:maven/org.hibernate/hibernate-core@5.5.9.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "172fb1b85d984035bd46d60e55e2f8acc20ebac024068b6e1b109faae2d617a8"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-0603 onto the 5.5.9.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.hibernate/hibernate-core@5.6.15.Final%2Bbackpatch.001",
    "group" : "org.hibernate",
    "name" : "hibernate-core",
    "version" : "5.6.15.Final+backpatch.001",
    "purl" : "pkg:maven/org.hibernate/hibernate-core@5.6.15.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "513ec0063b66896276457d9baed91076824c6e501b6ed098aaae5ad185094b42"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-0603 onto the 5.6.15.Final baseline.",
      "commits" : [ {
        "uid" : "3f820fdf16ee4d1f556bc73b259625416d703048",
        "url" : "https://github.com/hibernate/hibernate-orm/commit/3f820fdf16ee4d1f556bc73b259625416d703048"
      }, {
        "uid" : "6f4aae562b6eec9466959fa7a6dcfd34b57cf7d0",
        "url" : "https://github.com/hibernate/hibernate-orm/commit/6f4aae562b6eec9466959fa7a6dcfd34b57cf7d0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.1%2Bbackpatch.001",
    "group" : "org.apache.httpcomponents.client5",
    "name" : "httpclient5",
    "version" : "5.4.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6589c7aac8c5f15d05c49d6b26588fe43e3930aed49d75cddc57284a9c02ada1"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-27820 onto the 5.4.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.lowagie/itext@2.1.7%2Bbackpatch.001",
    "group" : "com.lowagie",
    "name" : "itext",
    "version" : "2.1.7+backpatch.001",
    "purl" : "pkg:maven/com.lowagie/itext@2.1.7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "269001a170208f904c131c9de5adfd854ac36392120af3ff52dff09fde159f87"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-9096 onto the 2.1.7 baseline.",
      "commits" : [ {
        "uid" : "aa4ac5f081150a80cc2f88b3bee50c68d57b29f7",
        "url" : "https://github.com/itext/itextpdf/commit/aa4ac5f081150a80cc2f88b3bee50c68d57b29f7"
      }, {
        "uid" : "ad4259e57412f4b538df3a57c55e814cfe748a72",
        "url" : "https://github.com/itext/itextpdf/commit/ad4259e57412f4b538df3a57c55e814cfe748a72"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.10.5.1+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "97705509e09a9026520e55205d87dfc77c9ac3c05da8e4b839dd33a9770e21e3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54513, CVE-2026-54512, CVE-2022-42003, CVE-2022-42004, CVE-2021-46877 onto the 2.10.5.1 baseline.",
      "commits" : [ {
        "uid" : "3ccde7d938fea547e598fdefe9a82cff37fed5cb",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/3ccde7d938fea547e598fdefe9a82cff37fed5cb"
      }, {
        "uid" : "cd090979b7ea78c75e4de8a4aed04f7e9fa8deea",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea"
      }, {
        "uid" : "7c0a74ee77a0896e9a3fde3600066ea0b7490f5b",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/7c0a74ee77a0896e9a3fde3600066ea0b7490f5b"
      }, {
        "uid" : "7ef87cbd0",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/7ef87cbd0"
      }, {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.11.4+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b0dc30ffc6d6395ad163c05ec9e9508d0945c66058f98a22fd1f2eb5c2ed63ed"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.11.4 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.12.7.2+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "08cd8c5a5a25d28ccab330565bed6adc3450548c4ae362e4fa0837bbbd2d926e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.12.7.2 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.13.5+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6ea19c923ef338b36dafea516a296c26d4a6189247b0fe26ceb58c1051829a19"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-50193, CVE-2026-54514, CVE-2026-54515 onto the 2.13.5 baseline.",
      "commits" : [ {
        "uid" : "7814533c845b05e3cf511a6c638761fe2cef0613",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/7814533c845b05e3cf511a6c638761fe2cef0613"
      }, {
        "uid" : "d2ba1ada807d3f71551e3826a9e787e0e5a6ac94",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/d2ba1ada807d3f71551e3826a9e787e0e5a6ac94"
      }, {
        "uid" : "ada34dcf6676aa5c5869791c23143a65a7bf56c2",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/ada34dcf6676aa5c5869791c23143a65a7bf56c2"
      }, {
        "uid" : "a1fa4ae4ecf5cee16da465985f135f3e81816f8c",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/a1fa4ae4ecf5cee16da465985f135f3e81816f8c"
      }, {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.14.3+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3020826bc1dada8cfe359483fe7dca73f2886acfefc523df1b0b6f92c1d33a25"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.14.3 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.15.4+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "0877c2cccaaecc20b5f6d554d157f3be20213cb3da8956562ee6757f159df92e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.15.4 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.16.2+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d3ce711a0d0cf51ad3e087b11b02cd2cb8323a8d82100b064c3aa64c647c2211"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.16.2 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.17.3+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "bf0d0046dbb678ac1640a9bb7c209f31efc0317baef4119acd7f33edbf4a633b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.17.3 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.19.4+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3e601802b3b6b2606041f836b1297a00c95387c63b3ae33bb5d3d0f90449016d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.19.4 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.20.2+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "45465f2fa27e49b10c8bee2622c3c966f24e0bc180a665537d9afeb37c0b6fc0"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-54512, CVE-2026-54513, CVE-2026-54514, CVE-2026-54515 onto the 2.20.2 baseline.",
      "commits" : [ {
        "uid" : "01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5"
      }, {
        "uid" : "434d6c511de7fdd9872f29157aafb6162d12d8d5",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5"
      }, {
        "uid" : "26a8c70bd42949ad72fbd9608e9f060ce661cb11",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/26a8c70bd42949ad72fbd9608e9f060ce661cb11"
      }, {
        "uid" : "2339bd43108a6dc8a0755dca91f03c599d7970f9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/2339bd43108a6dc8a0755dca91f03c599d7970f9"
      }, {
        "uid" : "1f5a1037b1e9e05920e755cb35f198bcd46667e4",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4"
      }, {
        "uid" : "bc1613c765704703ec7385e314fa8b19448e1ddd",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.10.8%2Bbackpatch.001",
    "group" : "com.fasterxml.jackson.core",
    "name" : "jackson-databind",
    "version" : "2.9.10.8+backpatch.001",
    "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.10.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "be8dbd4e97554632e45e525cc7d949fa7667edc1902b8ea65636b54231ea1daf"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-36518 onto the 2.9.10.8 baseline.",
      "commits" : [ {
        "uid" : "83b928dab9ba6ef81cf48987fcd12071e1ddb0c9",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/83b928dab9ba6ef81cf48987fcd12071e1ddb0c9"
      }, {
        "uid" : "fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b",
        "url" : "https://github.com/FasterXML/jackson-databind/commit/fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001",
    "group" : "org.codehaus.jackson",
    "name" : "jackson-core-asl",
    "version" : "1.9.13+backpatch.001",
    "purl" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e95be7c730672b27aa601fc74f8814e18d23eced61511700caad43010c938685"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-10202, CVE-2019-10172 onto the 1.9.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001",
    "group" : "org.codehaus.jackson",
    "name" : "jackson-mapper-asl",
    "version" : "1.9.13+backpatch.001",
    "purl" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "48081f92d7f5afdb2e01fe0a684f5c3835b7bfddb6413b0ff9dc93a55dd77d36"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-10202, CVE-2019-10172 onto the 1.9.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001",
    "group" : "net.sf.jasperreports",
    "name" : "jasperreports",
    "version" : "6.21.5+backpatch.001",
    "purl" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "978ca114f6fe24ab5f17d87a4942408880612b2690699184164ddfc9abc87362"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-10492, CVE-2026-6009 onto the 6.21.5 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001",
    "group" : "org.jboss.netty",
    "name" : "netty",
    "version" : "3.2.10.Final+backpatch.001",
    "purl" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "317ef4ed2720e81ad94bae13b9fbc9b36fd74316d0cd4e01db977b7e358ee09f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20444, CVE-2019-16869 onto the 3.2.10.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.jdom/jdom@1.1.3%2Bbackpatch.001",
    "group" : "org.jdom",
    "name" : "jdom",
    "version" : "1.1.3+backpatch.001",
    "purl" : "pkg:maven/org.jdom/jdom@1.1.3%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-33813 onto the 1.1.3 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "9.3.30.v20211001+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "07960e95fffea272bb1a77cdb2f7e6ace61fbde56533b28d6bca4755c01aa4ca"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-8184, CVE-2023-26048 onto the 9.3.30.v20211001 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.4.58.v20250814%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "9.4.58.v20250814+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.4.58.v20250814%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c6b04799b0b563e0cc0574e0fc4ec67b970941343b8da9521495e8baed7a4a18"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-2332 onto the 9.4.58.v20250814 baseline.",
      "commits" : [ {
        "uid" : "ff9eb742492d6dc3191bcd49668b1bce1e620d57",
        "url" : "https://github.com/jetty/jetty.project/commit/ff9eb742492d6dc3191bcd49668b1bce1e620d57"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.0.2.v20100331+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e62c81d23340e4cc16059435e504c6d128169e21ca1068568844869ffa326be5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.0.2.v20100331 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.0.2.v20100331+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7f7820402ac6ebb9101545fe781cc9a19f69028756cfb66e0735d4bfbc5bef05"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.0.2.v20100331 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.1.6.v20100715+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4cc488a39ec4b8b5584ce958360d830e7fbbd5a0c9260c01d7272d192fde5fc6"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.1.6.v20100715 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.1.6.v20100715+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f32206bc6d61f266ec684cb9f8a82504df927ec5a8be7eb93220f02de423202f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.1.6.v20100715 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.2.2.v20101205+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f6d8433db4f9d63d72e97d2650a72de884158bdc6b248aafd3b2ef2887ccae59"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.2.2.v20101205 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.2.2.v20101205+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f1d826b6ba591bf07810a14f999e336559719fa2063bca86431f13f8be8ad112"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.2.2.v20101205 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.3.1.v20110307+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "35f686b6004708b2ade2619df437d30cf37bd3dd69a42d3e9f9f8623ce33f5b7"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.3.1.v20110307 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.3.1.v20110307+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3974578dd1495ccd2a76532f08b77af37b4877f8eb3956d119ae0ceec311821f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.3.1.v20110307 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.4.5.v20110725+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "abfdd834b0f4d5643fb020b421aa38aa7ae23ceafa4f3142481207ded660db70"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.4.5.v20110725 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.4.5.v20110725+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "9541a02fbb8c3dbf1edd02fab0173479d8781d37ea68deeef7f2ced4657f929e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.4.5.v20110725 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.5.4.v20111024+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "a3bb449e9165a972619d842b5a15306b51422b4e3b328aff8d3f9a39baa0a76c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.5.4.v20111024 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.5.4.v20111024+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c57351a797ea97077e1df7a1f6a9430422069fd70e9b48f5271269f8a61d2c71"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.5.4.v20111024 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "7.6.21.v20160908+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d3e68187be34d8d20cd9293327d60b0fbc667bc165108a2b8d00588704d49124"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.6.21.v20160908 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "7.6.21.v20160908+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "2e0d7175868d9021592708493b92bfb1c77d225808d0343e46d6c72b764ff419"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 7.6.21.v20160908 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "8.0.4.v20111024+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1071c69d041fd2f63d530efd2cd6030992991c4d45fb08af6b21c9f0f0f7b668"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 8.0.4.v20111024 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "8.0.4.v20111024+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4c2a9adf62c2f17063a05756d0c3d9a7d5be9e63857b09ed8140a694def9135a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 8.0.4.v20111024 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "8.1.22.v20160922+backpatch.002",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "9f47afe18b2c932d5120c08c94ad0bb96ba036196db8a7af6a631cea6e7fa915"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 8.1.22.v20160922 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "8.1.22.v20160922+backpatch.002",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c344cc8c477c0bf401dc5bd813eb0ae2ead0f839a5a539b00cfad12248b6fb01"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 8.1.22.v20160922 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "8.2.0.v20160908+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c4be6e36befc7a521bf13872aef18335f99489fbf8242540ddc0c76fd941e200"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 8.2.0.v20160908 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "8.2.0.v20160908+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c6f1b6cea4ae4385953e405388aa2fd9bf38081e26dd5364e0e1256259497863"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658 onto the 8.2.0.v20160908 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "9.0.7.v20131107+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f7234c1d7d9b4b69139f0c29af2f830fa03e9b8a22d797086c6b01f3b3981f1a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658, CVE-2017-7656 onto the 9.0.7.v20131107 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "9.0.7.v20131107+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ee027f05889a7ff7ac4e757ae1e890178f7b16a33ebc0bba77f1e185f85997cb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658, CVE-2017-7656 onto the 9.0.7.v20131107 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-http",
    "version" : "9.1.6.v20160112+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "eeb1403ef41a88fc7e2e9b805efd37e926a82bce199c4674400bef08a4e808a6"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658, CVE-2017-7656 onto the 9.1.6.v20160112 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001",
    "group" : "org.eclipse.jetty",
    "name" : "jetty-server",
    "version" : "9.1.6.v20160112+backpatch.001",
    "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "faab9e7e7e1d8bc4d2077c814b450dbe11cf1e572b12e2673627eb0b942a45cb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2017-7657, CVE-2017-7658, CVE-2017-7656 onto the 9.1.6.v20160112 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.001",
    "group" : "org.jodd",
    "name" : "jodd-json",
    "version" : "5.0.3+backpatch.001",
    "purl" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2018-21234 onto the 5.0.3 baseline.",
      "commits" : [ {
        "uid" : "9bffc3913aeb8472c11bb543243004b4b4376f16",
        "url" : "https://github.com/oblac/jodd/commit/9bffc3913aeb8472c11bb543243004b4b4376f16"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.002",
    "group" : "org.jodd",
    "name" : "jodd-json",
    "version" : "5.0.3+backpatch.002",
    "purl" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.002",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2018-21234 onto the 5.0.3 baseline.",
      "commits" : [ {
        "uid" : "9bffc3913aeb8472c11bb543243004b4b4376f16",
        "url" : "https://github.com/oblac/jodd/commit/9bffc3913aeb8472c11bb543243004b4b4376f16"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/net.minidev/json-smart@1.3.3%2Bbackpatch.001",
    "group" : "net.minidev",
    "name" : "json-smart",
    "version" : "1.3.3+backpatch.001",
    "purl" : "pkg:maven/net.minidev/json-smart@1.3.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ea6fdf67d09437293993a25b4c74db1eaca7132de056147ebf83ca786afa8b68"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-1370 onto the 1.3.3 baseline.",
      "commits" : [ {
        "uid" : "5b3205d051952d3100aa0db1535f6ba6226bd87a",
        "url" : "https://github.com/netplex/json-smart-v1/commit/5b3205d051952d3100aa0db1535f6ba6226bd87a"
      }, {
        "uid" : "e2791ae506a57491bc856b439d706c81e45adcf8",
        "url" : "https://github.com/netplex/json-smart-v1/commit/e2791ae506a57491bc856b439d706c81e45adcf8"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.kafka/kafka-clients@2.8.2%2Bbackpatch.001",
    "group" : "org.apache.kafka",
    "name" : "kafka-clients",
    "version" : "2.8.2+backpatch.001",
    "purl" : "pkg:maven/org.apache.kafka/kafka-clients@2.8.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7511fb9f9dc9275b74ad013b12f14f747db3754e9cf0439815f2eb89d050c3e5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-35554 onto the 2.8.2 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.2.3%2Bbackpatch.001",
    "group" : "org.apache.kafka",
    "name" : "kafka-clients",
    "version" : "3.2.3+backpatch.001",
    "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.2.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "eb39508e6fd91cda99402dbe3f749bbef1623262b753dbc4b422df6251530c8f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-27817 onto the 3.2.3 baseline.",
      "commits" : [ {
        "uid" : "35829fddcbcf375eb0462d07a51bf8becb1b8757",
        "url" : "https://github.com/apache/kafka/commit/35829fddcbcf375eb0462d07a51bf8becb1b8757"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.001",
    "group" : "org.apache.kafka",
    "name" : "kafka-clients",
    "version" : "3.8.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-35554 onto the 3.8.1 baseline.",
      "commits" : [ {
        "uid" : "1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5",
        "url" : "https://github.com/apache/kafka/commit/1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002",
    "group" : "org.apache.kafka",
    "name" : "kafka-clients",
    "version" : "3.8.1+backpatch.002",
    "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "db92fcdd7330add6a82cabfad0028e96ab1c5bb530e0e4821d029c151197c50f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-35554, CVE-2025-27818 onto the 3.8.1 baseline.",
      "commits" : [ {
        "uid" : "1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5",
        "url" : "https://github.com/apache/kafka/commit/1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5"
      }, {
        "uid" : "8262e2315dacdf0c385ca7e1e28790f130f37bf1",
        "url" : "https://github.com/apache/kafka/commit/8262e2315dacdf0c385ca7e1e28790f130f37bf1"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
    "group" : "log4j",
    "name" : "log4j",
    "version" : "1.2.17+backpatch.001",
    "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-17571, CVE-2022-23305, CVE-2022-23302, CVE-2021-4104, CVE-2022-23307, CVE-2023-26464 onto the 1.2.17 baseline.",
      "commits" : [ {
        "uid" : "6051245a6243c1d1375f99ba29013f7ce877cc9f",
        "url" : "https://github.com/apache/logging-log4j1/commit/6051245a6243c1d1375f99ba29013f7ce877cc9f"
      }, {
        "uid" : "e845f28e7fb0ecbc0fcce383b11179f2650a51a2",
        "url" : "https://github.com/apache/logging-log4j1/commit/e845f28e7fb0ecbc0fcce383b11179f2650a51a2"
      }, {
        "uid" : "f221f2427c45134cf5768f46279ddf72fe1407c9",
        "url" : "https://github.com/apache/logging-log4j1/commit/f221f2427c45134cf5768f46279ddf72fe1407c9"
      }, {
        "uid" : "fb7b1ff1c8beb8544933248d00a46e9e30547e87",
        "url" : "https://github.com/apache/logging-log4j1/commit/fb7b1ff1c8beb8544933248d00a46e9e30547e87"
      }, {
        "uid" : "64902fe18ce5a5dd40487051a2f6231d9fbbe9b0",
        "url" : "https://github.com/apache/logging-log4j1/commit/64902fe18ce5a5dd40487051a2f6231d9fbbe9b0"
      }, {
        "uid" : "3a86b8e5b474cdda25a255c0d8ba3ad427f7ff58",
        "url" : "https://github.com/apache/logging-log4j1/commit/3a86b8e5b474cdda25a255c0d8ba3ad427f7ff58"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001",
    "group" : "org.apache.logging.log4j",
    "name" : "log4j-core",
    "version" : "2.14.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 onto the 2.14.1 baseline.",
      "commits" : [ {
        "uid" : "27972043b76c9645476f561c5adc483dec6d3f5d",
        "url" : "https://github.com/apache/logging-log4j2/commit/27972043b76c9645476f561c5adc483dec6d3f5d"
      }, {
        "uid" : "c362aff473e9812798ff8f25f30a2619996605d5",
        "url" : "https://github.com/apache/logging-log4j2/commit/c362aff473e9812798ff8f25f30a2619996605d5"
      }, {
        "uid" : "806023265f8c905b2dd1d81fd2458f64b2ea0b5e",
        "url" : "https://github.com/apache/logging-log4j2/commit/806023265f8c905b2dd1d81fd2458f64b2ea0b5e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001",
    "group" : "ch.qos.logback",
    "name" : "logback-classic",
    "version" : "1.1.11+backpatch.001",
    "purl" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "987f0b3e8380374d17b55bfe8266c522c1f01030e2b5a34fa37adad9b58044e4"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-12801, CVE-2025-11226 onto the 1.1.11 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001",
    "group" : "ch.qos.logback",
    "name" : "logback-core",
    "version" : "1.1.11+backpatch.001",
    "purl" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "42f9c82ec0cdcd8bfd128a86ae87061f99f44f72881c81b2e3e26da84dacbb29"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-12801, CVE-2025-11226 onto the 1.1.11 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001",
    "group" : "ch.qos.logback",
    "name" : "logback-classic",
    "version" : "1.2.13+backpatch.001",
    "purl" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "a536bda8dcfb8403c41e0ec43f2cf99d1d3d77dc09479f680ec795b2436dcbba"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-12801, CVE-2025-11226 onto the 1.2.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001",
    "group" : "ch.qos.logback",
    "name" : "logback-core",
    "version" : "1.2.13+backpatch.001",
    "purl" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "da8be16ce83b23528ff70af8bfb9fbfad3acdba1f7c576d5737061e9192ca597"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-12801, CVE-2025-11226 onto the 1.2.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.001",
    "group" : "org.apache.mina",
    "name" : "mina-core",
    "version" : "2.0.25+backpatch.001",
    "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "5d2094046ae445bd4e07b0ca0a395dc10e3857ca9ff456b0085a0a7bfec12e0e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-52046 onto the 2.0.25 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002",
    "group" : "org.apache.mina",
    "name" : "mina-core",
    "version" : "2.0.25+backpatch.002",
    "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "0eb491942e7dc3e1d76b375d09a1a6b5c4e3e25ab2a6bb21627afbe986deb4d5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-52046, CVE-2026-41409, CVE-2026-41635, CVE-2026-47065 onto the 2.0.25 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.3.1.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f4087724fd63dacaacb31d3311a866ad5016f6856605925b3ed2594bec5df6ef"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20444, CVE-2019-20445, CVE-2019-16869, CVE-2021-43797 onto the 3.3.1.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.4.6.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "09ce60b9e114e93ff7a99a92e7ca91013cf1bdd1efb32ba95190d353026a9b89"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2021-43797 onto the 3.4.6.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.5.13.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "9566f409876e57fda57ad23e01c4a57f2d7914d9f2cde2850db76036eb9e21a9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20444, CVE-2019-20445, CVE-2019-16869, CVE-2021-43797 onto the 3.5.13.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.6.10.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e97f1e3bebf006678f45f25953d4385c6941e42ce16723370f44ccfc5932c7fc"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2021-43797 onto the 3.6.10.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.7.1.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "cb8d7329e400ad42a6aaa3c88adaa7567b8fde57b9535e098145c328e8fe03c2"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2021-43797 onto the 3.7.1.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.8.3.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e8669366a59e0ec5ef8e3356671fe24e261a574d23b2317f06e1fb10d8566edd"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20444, CVE-2019-20445, CVE-2019-16869, CVE-2021-43797 onto the 3.8.3.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.9.9.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d1d9eb8e48699af918de7fd9f8f45130658cd29f3f603149a810e26d1d48e9be"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2021-43797 onto the 3.9.9.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.10.6.Final+backpatch.001",
    "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20445, CVE-2020-7238 onto the 3.10.6.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.10.6.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20445, CVE-2020-7238 onto the 3.10.6.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.10.6.Final+backpatch.003",
    "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20445, CVE-2020-7238 onto the 3.10.6.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
    "group" : "io.netty",
    "name" : "netty",
    "version" : "3.10.6.Final+backpatch.004",
    "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "a9b46a001c4ab98d2701b438cc98e020bb39219a98a201f7b9d97130e4457e66"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-20444, CVE-2019-16869, CVE-2021-43797, CVE-2019-20445, CVE-2020-7238 onto the 3.10.6.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty-buffer",
    "version" : "4.0.56.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "2982f0c81ee47f0c2dcbd0e421a5c9d35fc3f64dc7843ef389ac8bbc451347d9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444 onto the 4.0.56.Final baseline.",
      "commits" : [ {
        "uid" : "39cafcb05c99f2aa9fce7e6597664c9ed6a63a95",
        "url" : "https://github.com/netty/netty/commit/39cafcb05c99f2aa9fce7e6597664c9ed6a63a95"
      }, {
        "uid" : "a7c18d44b46e02dadfe3da225a06e5091f5f328e",
        "url" : "https://github.com/netty/netty/commit/a7c18d44b46e02dadfe3da225a06e5091f5f328e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty-codec-http",
    "version" : "4.0.56.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b4e817f1d0f7b8c76804ba61a7a00018e18d85bed9c0e01c2f29557186199327"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444 onto the 4.0.56.Final baseline.",
      "commits" : [ {
        "uid" : "39cafcb05c99f2aa9fce7e6597664c9ed6a63a95",
        "url" : "https://github.com/netty/netty/commit/39cafcb05c99f2aa9fce7e6597664c9ed6a63a95"
      }, {
        "uid" : "a7c18d44b46e02dadfe3da225a06e5091f5f328e",
        "url" : "https://github.com/netty/netty/commit/a7c18d44b46e02dadfe3da225a06e5091f5f328e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty-codec",
    "version" : "4.0.56.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "dca7c63a502e4f8ab50e83c235ea11895b9c0944a783f133c669c73343446a32"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444 onto the 4.0.56.Final baseline.",
      "commits" : [ {
        "uid" : "39cafcb05c99f2aa9fce7e6597664c9ed6a63a95",
        "url" : "https://github.com/netty/netty/commit/39cafcb05c99f2aa9fce7e6597664c9ed6a63a95"
      }, {
        "uid" : "a7c18d44b46e02dadfe3da225a06e5091f5f328e",
        "url" : "https://github.com/netty/netty/commit/a7c18d44b46e02dadfe3da225a06e5091f5f328e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty-common",
    "version" : "4.0.56.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8cc5a71a814fbdb04f4763a97340092c2bdf081dc88a68a25d47152502aab210"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444 onto the 4.0.56.Final baseline.",
      "commits" : [ {
        "uid" : "39cafcb05c99f2aa9fce7e6597664c9ed6a63a95",
        "url" : "https://github.com/netty/netty/commit/39cafcb05c99f2aa9fce7e6597664c9ed6a63a95"
      }, {
        "uid" : "a7c18d44b46e02dadfe3da225a06e5091f5f328e",
        "url" : "https://github.com/netty/netty/commit/a7c18d44b46e02dadfe3da225a06e5091f5f328e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty-handler",
    "version" : "4.0.56.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e9a225f2e2976dd59dc7f1ff0a91cd60b24a1fc85595ed2cc073759691c2aff5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444 onto the 4.0.56.Final baseline.",
      "commits" : [ {
        "uid" : "39cafcb05c99f2aa9fce7e6597664c9ed6a63a95",
        "url" : "https://github.com/netty/netty/commit/39cafcb05c99f2aa9fce7e6597664c9ed6a63a95"
      }, {
        "uid" : "a7c18d44b46e02dadfe3da225a06e5091f5f328e",
        "url" : "https://github.com/netty/netty/commit/a7c18d44b46e02dadfe3da225a06e5091f5f328e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002",
    "group" : "io.netty",
    "name" : "netty-transport",
    "version" : "4.0.56.Final+backpatch.002",
    "purl" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f2fb68f12917dc0c92917765510f0e727ff1a14559369839d3e6869f2ad44838"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-16869, CVE-2019-20444 onto the 4.0.56.Final baseline.",
      "commits" : [ {
        "uid" : "39cafcb05c99f2aa9fce7e6597664c9ed6a63a95",
        "url" : "https://github.com/netty/netty/commit/39cafcb05c99f2aa9fce7e6597664c9ed6a63a95"
      }, {
        "uid" : "a7c18d44b46e02dadfe3da225a06e5091f5f328e",
        "url" : "https://github.com/netty/netty/commit/a7c18d44b46e02dadfe3da225a06e5091f5f328e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.squareup.okhttp3/okhttp@3.14.9%2Bbackpatch.001",
    "group" : "com.squareup.okhttp3",
    "name" : "okhttp",
    "version" : "3.14.9+backpatch.001",
    "purl" : "pkg:maven/com.squareup.okhttp3/okhttp@3.14.9%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "602bfd71edc172a430ec4e7790c0c2456fedad1d0c0fa59c814543841194ec18"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-0341 onto the 3.14.9 baseline.",
      "commits" : [ {
        "uid" : "f574ea2f5259d9040f264ddeb582fb1ce563f10c",
        "url" : "https://github.com/square/okhttp/commit/f574ea2f5259d9040f264ddeb582fb1ce563f10c"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.0.2%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.0.2+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.0.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "2bd522b9b968f446c2f06d8c63cd6825dd59101c9547bbcd8ee3a4d28a104637"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.0.2 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.1.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.1.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.1.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3cb21227d7a267a66f1a0a480fc4c1765e0ddd3b4f02b422f5cb848bf94fe67d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.1.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.2.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.2.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.2.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "64677f501bc18ffd01c35e36bbcc7bca3a40ccaa0f3fb7d2678217980e118db2"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.2.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.3.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.3.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.3.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "36f8c29ef237249424f17bc64b20c473942e61fc56b221d0ca4b7ef27dd81c0d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.3.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.4.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.4.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.4.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "27c4f940e8a05fb70f6d1d9d015f75ee9aeaef83e0724bbbc6d053f4df397211"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.4.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.5.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.5.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.5.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "384d4df998af24ebad320c6f74b6441aef5ef95ed84162156821f5733d02e980"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.5.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.6.1%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.6.1+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.6.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4b35049110d46d46031b880348136e1e0d29791d19c0de8227fc5ede7b82c3df"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.6.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.7.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.7.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.7.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d2a217bbdcde38f2f29212a1878826c2bb7afa68d2c02e853434c0a9380a41e5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.7.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.8.3%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.8.3+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.8.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "24ff5074509553ff0f46f4f856cdb688363e3d3f7014c712667bd433e7b1587f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.8.3 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.001",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.9.0+backpatch.001",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.9.0 baseline.",
      "commits" : [ {
        "uid" : "e6a3fbc762b02c7950b1a76457aa4f5c062ef034",
        "url" : "https://github.com/pac4j/pac4j/commit/e6a3fbc762b02c7950b1a76457aa4f5c062ef034"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.002",
    "group" : "org.pac4j",
    "name" : "pac4j-core",
    "version" : "3.9.0+backpatch.002",
    "purl" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f1f81cbf3b362e05414017d50d6f5689bfaa31379784a230660606051dd8d9a1"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-25581 onto the 3.9.0 baseline.",
      "commits" : [ {
        "uid" : "e6a3fbc762b02c7950b1a76457aa4f5c062ef034",
        "url" : "https://github.com/pac4j/pac4j/commit/e6a3fbc762b02c7950b1a76457aa4f5c062ef034"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001",
    "group" : "org.ops4j.pax.logging",
    "name" : "pax-logging-log4j2",
    "version" : "1.8.7+backpatch.001",
    "purl" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "fa17ce86419aae6092603159bea747fc17806ee048d1b6499e05b64c6a713b1c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 onto the 1.8.7 baseline.",
      "commits" : [ {
        "uid" : "27972043b76c9645476f561c5adc483dec6d3f5d",
        "url" : "https://github.com/ops4j/org.ops4j.pax.logging/commit/27972043b76c9645476f561c5adc483dec6d3f5d"
      }, {
        "uid" : "c362aff473e9812798ff8f25f30a2619996605d5",
        "url" : "https://github.com/ops4j/org.ops4j.pax.logging/commit/c362aff473e9812798ff8f25f30a2619996605d5"
      }, {
        "uid" : "806023265f8c905b2dd1d81fd2458f64b2ea0b5e",
        "url" : "https://github.com/ops4j/org.ops4j.pax.logging/commit/806023265f8c905b2dd1d81fd2458f64b2ea0b5e"
      }, {
        "uid" : "c41eef8707c662fa3d2c98539291a968e8aa177b",
        "url" : "https://github.com/ops4j/org.ops4j.pax.logging/commit/c41eef8707c662fa3d2c98539291a968e8aa177b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.poi/poi-ooxml@3.17%2Bbackpatch.001",
    "group" : "org.apache.poi",
    "name" : "poi-ooxml",
    "version" : "3.17+backpatch.001",
    "purl" : "pkg:maven/org.apache.poi/poi-ooxml@3.17%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-12415 onto the 3.17 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001",
    "group" : "org.postgresql",
    "name" : "postgresql",
    "version" : "42.4.0+backpatch.001",
    "purl" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-1597, CVE-2022-31197 onto the 42.4.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.postgresql/postgresql@9.4.1212.jre7%2Bbackpatch.001",
    "group" : "org.postgresql",
    "name" : "postgresql",
    "version" : "9.4.1212.jre7+backpatch.001",
    "purl" : "pkg:maven/org.postgresql/postgresql@9.4.1212.jre7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b9ee02656398fc8accfd2aa7ceb4aec0432f24a9d228e2d95a0f398d041b56bb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-1597 onto the 9.4.1212.jre7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.protobuf/protobuf-java@2.4.1%2Bbackpatch.001",
    "group" : "com.google.protobuf",
    "name" : "protobuf-java",
    "version" : "2.4.1+backpatch.001",
    "purl" : "pkg:maven/com.google.protobuf/protobuf-java@2.4.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b656801e90f840d61e9989e316eaeda90c373af0d93537e2133da04e0531854b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-7254 onto the 2.4.1 baseline.",
      "commits" : [ {
        "uid" : "4728531c162f2f9e8c2ca1add713cfee2db6be3b",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/4728531c162f2f9e8c2ca1add713cfee2db6be3b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.protobuf/protobuf-java@2.5.0%2Bbackpatch.001",
    "group" : "com.google.protobuf",
    "name" : "protobuf-java",
    "version" : "2.5.0+backpatch.001",
    "purl" : "pkg:maven/com.google.protobuf/protobuf-java@2.5.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "67bc1073cab4f5462d95207490490dce9e73bc00a3b2cd5a01e78587a75a0753"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-7254 onto the 2.5.0 baseline.",
      "commits" : [ {
        "uid" : "4728531c162f2f9e8c2ca1add713cfee2db6be3b",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/4728531c162f2f9e8c2ca1add713cfee2db6be3b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.protobuf/protobuf-java@2.6.1%2Bbackpatch.001",
    "group" : "com.google.protobuf",
    "name" : "protobuf-java",
    "version" : "2.6.1+backpatch.001",
    "purl" : "pkg:maven/com.google.protobuf/protobuf-java@2.6.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4b491a337de3cb7f637ddf2d88bc40f2b1b65181a30f8b703210e60641cad6f1"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-7254 onto the 2.6.1 baseline.",
      "commits" : [ {
        "uid" : "4728531c162f2f9e8c2ca1add713cfee2db6be3b",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/4728531c162f2f9e8c2ca1add713cfee2db6be3b"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.001",
    "group" : "com.google.protobuf",
    "name" : "protobuf-java",
    "version" : "3.19.6+backpatch.001",
    "purl" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-7254 onto the 3.19.6 baseline.",
      "commits" : [ {
        "uid" : "4728531c162f2f9e8c2ca1add713cfee2db6be3b",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/4728531c162f2f9e8c2ca1add713cfee2db6be3b"
      }, {
        "uid" : "cc8b3483a5584b3301e3d43d17eb59704857ffaa",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/cc8b3483a5584b3301e3d43d17eb59704857ffaa"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.002",
    "group" : "com.google.protobuf",
    "name" : "protobuf-java",
    "version" : "3.19.6+backpatch.002",
    "purl" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d4c9af9b15c1135bdaf6dfbbb6cbe13d225578076e0847cf7440170f00c29211"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-7254 onto the 3.19.6 baseline.",
      "commits" : [ {
        "uid" : "4728531c162f2f9e8c2ca1add713cfee2db6be3b",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/4728531c162f2f9e8c2ca1add713cfee2db6be3b"
      }, {
        "uid" : "cc8b3483a5584b3301e3d43d17eb59704857ffaa",
        "url" : "https://github.com/protocolbuffers/protobuf/commit/cc8b3483a5584b3301e3d43d17eb59704857ffaa"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.quartz-scheduler/quartz@2.3.1%2Bbackpatch.001",
    "group" : "org.quartz-scheduler",
    "name" : "quartz",
    "version" : "2.3.1+backpatch.001",
    "purl" : "pkg:maven/org.quartz-scheduler/quartz@2.3.1%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2019-13990 onto the 2.3.1 baseline.",
      "commits" : [ {
        "uid" : "a1395ba118df306c7fe67c24fb0c9a95a4473140",
        "url" : "https://github.com/quartz-scheduler/quartz/commit/a1395ba118df306c7fe67c24fb0c9a95a4473140"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.projectreactor.netty/reactor-netty-core@1.0.19%2Bbackpatch.001",
    "group" : "io.projectreactor.netty",
    "name" : "reactor-netty-core",
    "version" : "1.0.19+backpatch.001",
    "purl" : "pkg:maven/io.projectreactor.netty/reactor-netty-core@1.0.19%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-34062 onto the 1.0.19 baseline.",
      "commits" : [ {
        "uid" : "780e487ddc99edef1f9cf7720db8eae2ba671da7",
        "url" : "https://github.com/reactor/reactor-netty/commit/780e487ddc99edef1f9cf7720db8eae2ba671da7"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.projectreactor.netty/reactor-netty-http@1.0.19%2Bbackpatch.001",
    "group" : "io.projectreactor.netty",
    "name" : "reactor-netty-http",
    "version" : "1.0.19+backpatch.001",
    "purl" : "pkg:maven/io.projectreactor.netty/reactor-netty-http@1.0.19%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-34062 onto the 1.0.19 baseline.",
      "commits" : [ {
        "uid" : "780e487ddc99edef1f9cf7720db8eae2ba671da7",
        "url" : "https://github.com/reactor/reactor-netty/commit/780e487ddc99edef1f9cf7720db8eae2ba671da7"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.yaml/snakeyaml@1.33%2Bbackpatch.001",
    "group" : "org.yaml",
    "name" : "snakeyaml",
    "version" : "1.33+backpatch.001",
    "purl" : "pkg:maven/org.yaml/snakeyaml@1.33%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "998cd3acb23ae45baf91b67f5bc059cd23a84adad5399d409f9a0c58f8b5db2c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-1471 onto the 1.33 baseline.",
      "commits" : [ {
        "uid" : "59ddbb3304bb8e22e2004d74cddaf9ed4086632e",
        "url" : "https://github.com/https://bitbucket.org/snakeyaml/snakeyaml.git/commit/59ddbb3304bb8e22e2004d74cddaf9ed4086632e"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.solr/solr-core@8.11.4%2Bbackpatch.001",
    "group" : "org.apache.solr",
    "name" : "solr-core",
    "version" : "8.11.4+backpatch.001",
    "purl" : "pkg:maven/org.apache.solr/solr-core@8.11.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "cd2a01ed2f9af26a337076702235ec35c6c242ffcd02a62a8b8e2da233eee3b3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22022 onto the 8.11.4 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001",
    "group" : "org.apache.spark",
    "name" : "spark-core_2.11",
    "version" : "2.4.8+backpatch.001",
    "purl" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4f6882bc0588ebf66d404bfe5ae339f8525ac33f7b5feadeb491bdadd992fa05"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-22946, CVE-2025-54920 onto the 2.4.8 baseline.",
      "commits" : [ {
        "uid" : "909da96e1471886a01a9e1def93630c4fd40e74a",
        "url" : "https://github.com/apache/spark/commit/909da96e1471886a01a9e1def93630c4fd40e74a"
      }, {
        "uid" : "a53a9c4d77377af9fbd648a8d9b528754d657aea",
        "url" : "https://github.com/apache/spark/commit/a53a9c4d77377af9fbd648a8d9b528754d657aea"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001",
    "group" : "org.apache.spark",
    "name" : "spark-core_2.12",
    "version" : "3.0.3+backpatch.001",
    "purl" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b5406a0fe865a2f5b13541805657de0036b9f84ffeeccd32cf85d28ef870662d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-22946, CVE-2025-54920 onto the 3.0.3 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.boot",
    "name" : "spring-boot-autoconfigure",
    "version" : "1.5.22.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "bdcf5c16ee1ea378ae564c8b0d8552755628f41d0bcc97aa901861d0cd5c1abf"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-27772, CVE-2023-20883 onto the 1.5.22.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.boot",
    "name" : "spring-boot",
    "version" : "1.5.22.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4a73eef8b4f5df6eefb1036558b7ca44127b6169801dec8dab8b8298c0d9c411"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-27772, CVE-2023-20883 onto the 1.5.22.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.002",
    "group" : "org.springframework.boot",
    "name" : "spring-boot-actuator-autoconfigure",
    "version" : "2.7.18+backpatch.002",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.002",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22733 onto the 2.7.18 baseline.",
      "commits" : [ {
        "uid" : "01fbede2b27237616e215fe0df7c294ae47bdd73",
        "url" : "https://github.com/spring-projects/spring-boot/commit/01fbede2b27237616e215fe0df7c294ae47bdd73"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.002",
    "group" : "org.springframework.boot",
    "name" : "spring-boot-actuator",
    "version" : "2.7.18+backpatch.002",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.002",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22733 onto the 2.7.18 baseline.",
      "commits" : [ {
        "uid" : "01fbede2b27237616e215fe0df7c294ae47bdd73",
        "url" : "https://github.com/spring-projects/spring-boot/commit/01fbede2b27237616e215fe0df7c294ae47bdd73"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.003",
    "group" : "org.springframework.boot",
    "name" : "spring-boot-actuator-autoconfigure",
    "version" : "2.7.18+backpatch.003",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.003",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22733 onto the 2.7.18 baseline.",
      "commits" : [ {
        "uid" : "01fbede2b27237616e215fe0df7c294ae47bdd73",
        "url" : "https://github.com/spring-projects/spring-boot/commit/01fbede2b27237616e215fe0df7c294ae47bdd73"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.003",
    "group" : "org.springframework.boot",
    "name" : "spring-boot-actuator",
    "version" : "2.7.18+backpatch.003",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.003",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22733 onto the 2.7.18 baseline.",
      "commits" : [ {
        "uid" : "01fbede2b27237616e215fe0df7c294ae47bdd73",
        "url" : "https://github.com/spring-projects/spring-boot/commit/01fbede2b27237616e215fe0df7c294ae47bdd73"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.boot/spring-boot-devtools@2.7.18%2Bbackpatch.001",
    "group" : "org.springframework.boot",
    "name" : "spring-boot-devtools",
    "version" : "2.7.18+backpatch.001",
    "purl" : "pkg:maven/org.springframework.boot/spring-boot-devtools@2.7.18%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "19887caaf4ba20d852f15685089fd4339d409532c18be911734f39cd0278a1e4"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40972 onto the 2.7.18 baseline.",
      "commits" : [ {
        "uid" : "4b0862cc00815a47b22339d7eac7ddc3b6645bd4",
        "url" : "https://github.com/spring-projects/spring-boot/commit/4b0862cc00815a47b22339d7eac7ddc3b6645bd4"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-config-server",
    "version" : "3.1.10+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "2ead94c6b153e55748c1b0dd1094fd2ccdc1d3e0902ba2a797b2f6d7c29faef2"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40982, CVE-2026-22739, CVE-2026-41002 onto the 3.1.10 baseline.",
      "commits" : [ {
        "uid" : "1870f07befd5f62edcfdaea5ad82441d0fd49912",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/1870f07befd5f62edcfdaea5ad82441d0fd49912"
      }, {
        "uid" : "80de5a5b67a07898e13fd04cf7402f9e8dfecb06",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/80de5a5b67a07898e13fd04cf7402f9e8dfecb06"
      }, {
        "uid" : "7709cd0e016ce879e195620cf706bb30682073d4",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/7709cd0e016ce879e195620cf706bb30682073d4"
      }, {
        "uid" : "cc71e5c3077732d44f0ef3afa439a0f73d6e70ce",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/cc71e5c3077732d44f0ef3afa439a0f73d6e70ce"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-config-server",
    "version" : "4.1.7+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ce9402a609d06bc0d712f4f7d5ef2b78261eb975636ee149e1d0396142570893"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40982, CVE-2026-22739, CVE-2026-40981, CVE-2026-41002 onto the 4.1.7 baseline.",
      "commits" : [ {
        "uid" : "1870f07befd5f62edcfdaea5ad82441d0fd49912",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/1870f07befd5f62edcfdaea5ad82441d0fd49912"
      }, {
        "uid" : "80de5a5b67a07898e13fd04cf7402f9e8dfecb06",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/80de5a5b67a07898e13fd04cf7402f9e8dfecb06"
      }, {
        "uid" : "7709cd0e016ce879e195620cf706bb30682073d4",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/7709cd0e016ce879e195620cf706bb30682073d4"
      }, {
        "uid" : "cc71e5c3077732d44f0ef3afa439a0f73d6e70ce",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/cc71e5c3077732d44f0ef3afa439a0f73d6e70ce"
      }, {
        "uid" : "dec2b524fc2f2170dbee95d0412c0f63412ecf28",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/dec2b524fc2f2170dbee95d0412c0f63412ecf28"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-config-server",
    "version" : "4.2.4+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "93e7865374bc93554ccf2b7996d5b58ce776f7f9d2ff03889e3c6bab7f206563"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40982, CVE-2026-22739, CVE-2026-41002 onto the 4.2.4 baseline.",
      "commits" : [ {
        "uid" : "7709cd0e016ce879e195620cf706bb30682073d4",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/7709cd0e016ce879e195620cf706bb30682073d4"
      }, {
        "uid" : "80de5a5b67a07898e13fd04cf7402f9e8dfecb06",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/80de5a5b67a07898e13fd04cf7402f9e8dfecb06"
      }, {
        "uid" : "cc71e5c3077732d44f0ef3afa439a0f73d6e70ce",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/cc71e5c3077732d44f0ef3afa439a0f73d6e70ce"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-config-server",
    "version" : "4.2.4+backpatch.002",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8e0692691ed63b559865625500c0e943d1513b71e8a532b0fa87a45b9a786a98"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40982, CVE-2026-22739, CVE-2026-41002, CVE-2026-40981 onto the 4.2.4 baseline.",
      "commits" : [ {
        "uid" : "7709cd0e016ce879e195620cf706bb30682073d4",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/7709cd0e016ce879e195620cf706bb30682073d4"
      }, {
        "uid" : "80de5a5b67a07898e13fd04cf7402f9e8dfecb06",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/80de5a5b67a07898e13fd04cf7402f9e8dfecb06"
      }, {
        "uid" : "dec2b524fc2f2170dbee95d0412c0f63412ecf28",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/dec2b524fc2f2170dbee95d0412c0f63412ecf28"
      }, {
        "uid" : "cc71e5c3077732d44f0ef3afa439a0f73d6e70ce",
        "url" : "https://github.com/spring-cloud/spring-cloud-config/commit/cc71e5c3077732d44f0ef3afa439a0f73d6e70ce"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-function-context@3.1.6%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-function-context",
    "version" : "3.1.6+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-function-context@3.1.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6e977ff223351b4ad6ea77ee72973adf7f41a4e68a34a9f1768b542933b5e2d2"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22963 onto the 3.1.6 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-function-core@3.1.6%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-function-core",
    "version" : "3.1.6+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-function-core@3.1.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6e1c07748e0aa49e9c14448a56627ccfa61feaa11f22077993cdf5b6a405b353"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22963 onto the 3.1.6 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-gateway-server",
    "version" : "2.2.10.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e5d056a71dda491eb47b892fa3690f83a665f021fcbb76a87e54aa1fdb758caa"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22947, CVE-2025-41235 onto the 2.2.10.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@3.0.6%2Bbackpatch.001",
    "group" : "org.springframework.cloud",
    "name" : "spring-cloud-gateway-server",
    "version" : "3.0.6+backpatch.001",
    "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@3.0.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "66be0dd65e14fe8aa21cf46efb0e2a6b09d019e9bd1df9e462b801c5e5fa1063"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22947 onto the 3.0.6 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.1.15%2Bbackpatch.001",
    "group" : "org.springframework.data",
    "name" : "spring-data-mongodb",
    "version" : "3.1.15+backpatch.001",
    "purl" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.1.15%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6a2bf42ca99a83afad14f4f94ab05c62f7889dedbed1b38987ec2689c2d7c508"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22980 onto the 3.1.15 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.2.12%2Bbackpatch.001",
    "group" : "org.springframework.data",
    "name" : "spring-data-mongodb",
    "version" : "3.2.12+backpatch.001",
    "purl" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.2.12%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "27775914ff4b1d3ad8440341b687d79359140fec04a9f52808236c63b82078ad"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22980 onto the 3.2.12 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "4.3.30.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262 onto the 4.3.30.RELEASE baseline.",
      "commits" : [ {
        "uid" : "7ec5c994c147f0e168149498b1c9d4a249d69e87",
        "url" : "https://github.com/spring-projects/spring-framework/commit/7ec5c994c147f0e168149498b1c9d4a249d69e87"
      }, {
        "uid" : "297cbae2990e1413537c55845a7e0ea0ffd9f9bb",
        "url" : "https://github.com/spring-projects/spring-framework/commit/297cbae2990e1413537c55845a7e0ea0ffd9f9bb"
      }, {
        "uid" : "7678286fb3efa7bd7719ffe3055da9ed01e9f2f9",
        "url" : "https://github.com/spring-projects/spring-framework/commit/7678286fb3efa7bd7719ffe3055da9ed01e9f2f9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "4.3.30.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262 onto the 4.3.30.RELEASE baseline.",
      "commits" : [ {
        "uid" : "7ec5c994c147f0e168149498b1c9d4a249d69e87",
        "url" : "https://github.com/spring-projects/spring-framework/commit/7ec5c994c147f0e168149498b1c9d4a249d69e87"
      }, {
        "uid" : "297cbae2990e1413537c55845a7e0ea0ffd9f9bb",
        "url" : "https://github.com/spring-projects/spring-framework/commit/297cbae2990e1413537c55845a7e0ea0ffd9f9bb"
      }, {
        "uid" : "7678286fb3efa7bd7719ffe3055da9ed01e9f2f9",
        "url" : "https://github.com/spring-projects/spring-framework/commit/7678286fb3efa7bd7719ffe3055da9ed01e9f2f9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "5.0.20.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "5617fd140565d2967eb89b11c471d44fec2f6daf60fb3b24655f6aae0c62e4c2"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262 onto the 5.0.20.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "5.1.20.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1afddafbe67eaf6d96dc57805871aec825b8fd571812bc4ae720f63372e61a27"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262 onto the 5.1.20.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
    "group" : "org.springframework",
    "name" : "spring-beans",
    "version" : "5.1.20.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "63d066a516e43f29c6e74ef8abfde6511c71a9241a2140e9af9602dcf4fcabd5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262, CVE-2022-22965, CVE-2026-41845 onto the 5.1.20.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "5.1.20.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8f79ac78087098d1392080021d8720d6edaecfda452e0b1cbf0bcb95df0762e3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262, CVE-2022-22965, CVE-2026-41845 onto the 5.1.20.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "5.2.25.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8e23835666c1ff8a0a15b7db7b8dc4de803d9dea1eff521c213cb7be930e3d48"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-22243, CVE-2024-22259, CVE-2024-22262, CVE-2026-41845 onto the 5.2.25.RELEASE baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-aop@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-aop",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-aop@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-beans@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-beans",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-beans@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-context@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-context",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-context@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-core@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-core",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-core@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-expression@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-expression",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-expression@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-jdbc@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-jdbc",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-jdbc@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-messaging@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-messaging",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-messaging@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-orm@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-orm",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-orm@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-test@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-test",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-test@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-tx@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-tx",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-tx@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-web@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-webflux@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-webflux",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-webflux@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-webmvc@5.3.39%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-webmvc",
    "version" : "5.3.39+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-webmvc@5.3.39%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-38816 onto the 5.3.39 baseline.",
      "commits" : [ {
        "uid" : "d86bf8b2056429edf5494456cffcb2b243331c49",
        "url" : "https://github.com/spring-projects/spring-framework/commit/d86bf8b2056429edf5494456cffcb2b243331c49"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.001",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "6.1.21+backpatch.001",
    "purl" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "46f8b0ece6830d8f8fd08efbcea5f175d23cf62b608db09d3266c69877ce1dae"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-41845 onto the 6.1.21 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002",
    "group" : "org.springframework",
    "name" : "spring-core",
    "version" : "6.1.21+backpatch.002",
    "purl" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "867be95c54ebfc5c7584dcf4a06385b866e880668c08c50685474d05b89b261e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-41845, CVE-2026-41848 onto the 6.1.21 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002",
    "group" : "org.springframework",
    "name" : "spring-web",
    "version" : "6.1.21+backpatch.002",
    "purl" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "bae8066cad405e05c82112f5ad0f7ab0a197a29ac8d512dcec0c49a470455815"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-41845, CVE-2026-41848 onto the 6.1.21 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001",
    "group" : "org.springframework.hateoas",
    "name" : "spring-hateoas",
    "version" : "1.5.6+backpatch.001",
    "purl" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "586098c8593c3eb903183d54cec857fce20662641715032af52f1bd9392da56a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-41007, CVE-2026-41006 onto the 1.5.6 baseline.",
      "commits" : [ {
        "uid" : "668fd3282e1c7ffc817499b4b3d85d3aa21c0c2e",
        "url" : "https://github.com/spring-projects/spring-hateoas/commit/668fd3282e1c7ffc817499b4b3d85d3aa21c0c2e"
      }, {
        "uid" : "2c127edd741e43e6e6f06f4081af92d400209990",
        "url" : "https://github.com/spring-projects/spring-hateoas/commit/2c127edd741e43e6e6f06f4081af92d400209990"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.integration/spring-integration-zip@1.0.0.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.integration",
    "name" : "spring-integration-zip",
    "version" : "1.0.0.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.integration/spring-integration-zip@1.0.0.RELEASE%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2018-1263 onto the 1.0.0.RELEASE baseline.",
      "commits" : [ {
        "uid" : "a5573eb232ff85199ff9bb28993df715d9a19a25",
        "url" : "https://github.com/spring-projects/spring-integration-extensions/commit/a5573eb232ff85199ff9bb28993df715d9a19a25"
      }, {
        "uid" : "8d1752c",
        "url" : "https://github.com/spring-projects/spring-integration-extensions/commit/8d1752c"
      }, {
        "uid" : "d10f537",
        "url" : "https://github.com/spring-projects/spring-integration-extensions/commit/d10f537"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.kafka/spring-kafka@2.8.11%2Bbackpatch.001",
    "group" : "org.springframework.kafka",
    "name" : "spring-kafka",
    "version" : "2.8.11+backpatch.001",
    "purl" : "pkg:maven/org.springframework.kafka/spring-kafka@2.8.11%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-34040 onto the 2.8.11 baseline.",
      "commits" : [ {
        "uid" : "eb779679812f61a8553ced3d0e4069dca65560ed",
        "url" : "https://github.com/spring-projects/spring-kafka/commit/eb779679812f61a8553ced3d0e4069dca65560ed"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.ldap/spring-ldap-core@2.4.4%2Bbackpatch.001",
    "group" : "org.springframework.ldap",
    "name" : "spring-ldap-core",
    "version" : "2.4.4+backpatch.001",
    "purl" : "pkg:maven/org.springframework.ldap/spring-ldap-core@2.4.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8ff4db455dbf4e298dec6ca1bb0eb926d00180d0bb87d60250c26964352c4121"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-41720 onto the 2.4.4 baseline.",
      "commits" : [ {
        "uid" : "e2748d44bdce4f6cb4663b9b8d8462e34808f09c",
        "url" : "https://github.com/spring-projects/spring-ldap/commit/e2748d44bdce4f6cb4663b9b8d8462e34808f09c"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "4.2.20.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22978, CVE-2021-22112, CVE-2024-22257 onto the 4.2.20.RELEASE baseline.",
      "commits" : [ {
        "uid" : "1a9ec8a7565059ab73b2825375b23f14d0d4525c",
        "url" : "https://github.com/spring-projects/spring-security/commit/1a9ec8a7565059ab73b2825375b23f14d0d4525c"
      }, {
        "uid" : "7cab7b06c51ea885dd0d07ff26b135dd3afce1d1",
        "url" : "https://github.com/spring-projects/spring-security/commit/7cab7b06c51ea885dd0d07ff26b135dd3afce1d1"
      }, {
        "uid" : "5a7f12f1a9fdb4edaab6f61495f1d781a7273b61",
        "url" : "https://github.com/spring-projects/spring-security/commit/5a7f12f1a9fdb4edaab6f61495f1d781a7273b61"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "4.2.20.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22978, CVE-2021-22112, CVE-2024-22257 onto the 4.2.20.RELEASE baseline.",
      "commits" : [ {
        "uid" : "1a9ec8a7565059ab73b2825375b23f14d0d4525c",
        "url" : "https://github.com/spring-projects/spring-security/commit/1a9ec8a7565059ab73b2825375b23f14d0d4525c"
      }, {
        "uid" : "7cab7b06c51ea885dd0d07ff26b135dd3afce1d1",
        "url" : "https://github.com/spring-projects/spring-security/commit/7cab7b06c51ea885dd0d07ff26b135dd3afce1d1"
      }, {
        "uid" : "5a7f12f1a9fdb4edaab6f61495f1d781a7273b61",
        "url" : "https://github.com/spring-projects/spring-security/commit/5a7f12f1a9fdb4edaab6f61495f1d781a7273b61"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "4.2.20.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "a804eb18efea484c62e5bde7dfc1bfdec94bb6ea50d73144c4fe2a9b70f9a6c5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22978, CVE-2021-22112, CVE-2024-22257, CVE-2026-22732, CVE-2024-38827 onto the 4.2.20.RELEASE baseline.",
      "commits" : [ {
        "uid" : "1a9ec8a7565059ab73b2825375b23f14d0d4525c",
        "url" : "https://github.com/spring-projects/spring-security/commit/1a9ec8a7565059ab73b2825375b23f14d0d4525c"
      }, {
        "uid" : "7cab7b06c51ea885dd0d07ff26b135dd3afce1d1",
        "url" : "https://github.com/spring-projects/spring-security/commit/7cab7b06c51ea885dd0d07ff26b135dd3afce1d1"
      }, {
        "uid" : "5a7f12f1a9fdb4edaab6f61495f1d781a7273b61",
        "url" : "https://github.com/spring-projects/spring-security/commit/5a7f12f1a9fdb4edaab6f61495f1d781a7273b61"
      }, {
        "uid" : "1dae9aa459436e0bb1a95701ed0d31e12be7788a",
        "url" : "https://github.com/spring-projects/spring-security/commit/1dae9aa459436e0bb1a95701ed0d31e12be7788a"
      }, {
        "uid" : "0eaffb37e7",
        "url" : "https://github.com/spring-projects/spring-security/commit/0eaffb37e7"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "4.2.20.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8c224440287b5010566237536d09099a2204fa651b6531648cdbb9c58c7a8582"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-22978, CVE-2021-22112, CVE-2024-22257, CVE-2026-22732, CVE-2024-38827 onto the 4.2.20.RELEASE baseline.",
      "commits" : [ {
        "uid" : "1a9ec8a7565059ab73b2825375b23f14d0d4525c",
        "url" : "https://github.com/spring-projects/spring-security/commit/1a9ec8a7565059ab73b2825375b23f14d0d4525c"
      }, {
        "uid" : "7cab7b06c51ea885dd0d07ff26b135dd3afce1d1",
        "url" : "https://github.com/spring-projects/spring-security/commit/7cab7b06c51ea885dd0d07ff26b135dd3afce1d1"
      }, {
        "uid" : "5a7f12f1a9fdb4edaab6f61495f1d781a7273b61",
        "url" : "https://github.com/spring-projects/spring-security/commit/5a7f12f1a9fdb4edaab6f61495f1d781a7273b61"
      }, {
        "uid" : "1dae9aa459436e0bb1a95701ed0d31e12be7788a",
        "url" : "https://github.com/spring-projects/spring-security/commit/1dae9aa459436e0bb1a95701ed0d31e12be7788a"
      }, {
        "uid" : "0eaffb37e7",
        "url" : "https://github.com/spring-projects/spring-security/commit/0eaffb37e7"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001",
    "group" : "org.springframework.security.oauth",
    "name" : "spring-security-oauth2",
    "version" : "2.0.9.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7d490ca4d00823d796710486466fb4e19256b63ec71cf5b44ef90962fa71464b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-4977, CVE-2018-1260, CVE-2019-3778 onto the 2.0.9.RELEASE baseline.",
      "commits" : [ {
        "uid" : "05166db04d61f24067db253cdebd7fea2bcf3d80",
        "url" : "https://github.com/spring-attic/spring-security-oauth/commit/05166db04d61f24067db253cdebd7fea2bcf3d80"
      }, {
        "uid" : "da157a89402eeb2d5d071db3558c3b417bfc3ed0",
        "url" : "https://github.com/spring-attic/spring-security-oauth/commit/da157a89402eeb2d5d071db3558c3b417bfc3ed0"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@5.5.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "5.5.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.5.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "2d99d0b2260b936bca2401ec55e174f122d29b6fd7a5a22407e7c1869086eaaf"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-31690 onto the 5.5.8 baseline.",
      "commits" : [ {
        "uid" : "e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f",
        "url" : "https://github.com/spring-projects/spring-security/commit/e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.5.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "5.5.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.5.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "bafa2cac838b23ac85461b76651c4c3309146c8f34229a16842a133717ece6a9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-31690 onto the 5.5.8 baseline.",
      "commits" : [ {
        "uid" : "e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f",
        "url" : "https://github.com/spring-projects/spring-security/commit/e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-oauth2-client@5.5.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-oauth2-client",
    "version" : "5.5.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-oauth2-client@5.5.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "b51cb601877a1836950b1283e065cfc70b2abd1c0bb848f95cf6dcafbaccf97f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-31690 onto the 5.5.8 baseline.",
      "commits" : [ {
        "uid" : "e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f",
        "url" : "https://github.com/spring-projects/spring-security/commit/e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-oauth2-core@5.5.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-oauth2-core",
    "version" : "5.5.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-oauth2-core@5.5.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d70227708e65e31fb2d53b69d8dd22a7eee0ac773c965905fe83e101eaaf8880"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-31690 onto the 5.5.8 baseline.",
      "commits" : [ {
        "uid" : "e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f",
        "url" : "https://github.com/spring-projects/spring-security/commit/e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@5.5.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "5.5.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.5.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "fb651a1b00914e1c6a3c191bfd4f39c961c2011b673e7e10cf66146b4a16536c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-31690 onto the 5.5.8 baseline.",
      "commits" : [ {
        "uid" : "e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f",
        "url" : "https://github.com/spring-projects/spring-security/commit/e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "5.6.12+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ea161e56b1edd250bfb84fe405b2c0447c350c78214f6aabf645cf96eaa663bd"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.6.12 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "5.6.12+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d985ebeb4863b74cfe8bbcad172622268448e290225b5d8e71548a884f543e38"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.6.12 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "5.6.12+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "462a6bc8f4ad2560f915ca510b71adf06a06c9ab46f8b63d179e5138a660e398"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.6.12 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "5.6.12+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4287403b8e95dab826cf68720456b0c2268d2c31079678815515c2fdf28df55b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.6.12 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "5.8.16+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7981b9a2d806398c364ee489a46166df87bfde6bbd50f6097a453816553bed03"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.8.16 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "5.8.16+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "bd5914aa9053a501c0e2bb9c7279de63f8a5535e9868be3d37e5323ba161fc85"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.8.16 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "5.8.16+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "9cb925dbf0b5b2ba62752bec41074d4c7d3c5497c40df169560b378bfb59a387"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.8.16 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "5.8.16+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ea138cad4039007e3de288d885d20cd9673ffad14e8f187429f2bfd15cb2b6c6"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-22228, CVE-2026-22732 onto the 5.8.16 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "5.7.14+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "5.7.14+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "5.7.14+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "null"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "5.7.14+backpatch.002",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "0eb15300e75e08bc10eb83fdafcbbc619cb0d9fc8e5a1c4593ada7343ce31fd5"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      }, {
        "uid" : "46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3",
        "url" : "https://github.com/spring-projects/spring-security/commit/46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "5.7.14+backpatch.002",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "dd5ed4416c28f8a51a87875a08e132a6854af20d1b68316fa42a56072a27093c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      }, {
        "uid" : "46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3",
        "url" : "https://github.com/spring-projects/spring-security/commit/46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "5.7.14+backpatch.002",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3c0282b4f62d0bf033de4f0d5c0426813788284b2e1f34ddabc250cf4017bbdf"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      }, {
        "uid" : "46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3",
        "url" : "https://github.com/spring-projects/spring-security/commit/46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "5.7.14+backpatch.002",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f030d34bd278b0ffe9fd3d72851420f7a16ff3c7c1e1a5e28a06339409ccbc06"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 5.7.14 baseline.",
      "commits" : [ {
        "uid" : "2e44a7c0c532fd2b096ce8ac676d690114b21afd",
        "url" : "https://github.com/spring-projects/spring-security/commit/2e44a7c0c532fd2b096ce8ac676d690114b21afd"
      }, {
        "uid" : "46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3",
        "url" : "https://github.com/spring-projects/spring-security/commit/46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "6.0.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f878e7330157b3fbf1ed160a679582e617a37c0eeddfbb40ae482fb6d67e5331"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.0.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "6.0.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "891b279f1482c17342f0150f67bc9ca31c49f8ea52fd8263eff210298c398322"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.0.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "6.0.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "94015d361b0a3bcc713cd8cc0230f69a8392666f8db244542eddd356f996bdd8"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.0.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "6.0.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8734c87268db3fde4d331413b63fb3ae5f3fa61216206448708aee0025cd0adb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.0.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "6.1.9+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f9ab84b435366db6da624f2d0e0507108d7746dcad6bddd37342c8846885ddef"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.1.9 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "6.1.9+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d7e1ded3a9c0c6c509ea9cabf8cbced1e1921c377d7da44ea2887d04a2e40e28"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.1.9 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "6.1.9+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1a23c50d1a9067e3437d533da1c00f803f6c8d787cdc267e8e3c491961a06915"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.1.9 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "6.1.9+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "59fa2916deec91e47585b5b82ce1a552cae0bc673bcfc9c18097980c9399c4af"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.1.9 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "6.2.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6e047f3a4cef94d96ef0d55dc4bec5cdf04d3f7ea8e37e868d9ad0b91f4ee00e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.2.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "6.2.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "327714680e035de0c141b54c441eb0414abec5bd76901a3055f52cc2de5b6df1"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.2.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "6.2.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "9de8eeb200305f91241b076221b09a804ef5a00ec13801e9bb99ede1aaf345d9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.2.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "6.2.8+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "5ff46a66cdece44f1500d98b174ee1e8d5cf6a83c510c9e0ec9d5301cee56c4f"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732, CVE-2025-22228 onto the 6.2.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@6.3.10%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "6.3.10+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.3.10%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "02dbfdcaff3e5ccf33058b40f6d07a9a932de1287684fb74a3882bbf50c08477"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.3.10 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@6.3.10%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "6.3.10+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.3.10%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ab457e8c7986d7fea97704c18019880c7326fd25b6ba47c815475dcf8f19edcc"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.3.10 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.3.10%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "6.3.10+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.3.10%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e781d196c027ce206a5c7fe354f369c66aabc11d11feda9c0d6adfa5a32a377c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.3.10 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@6.3.10%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "6.3.10+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.3.10%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "705a8f91d8222f6ff0ed7a0bb2ccba605a240434f4c12836f61e589100d5a7c8"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.3.10 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-config@6.4.13%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-config",
    "version" : "6.4.13+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.4.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "97c5d3d7cc12d2eb0688932e21ef7fe55a71d7d70151b81b6fd5174d5902c44b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.4.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-core@6.4.13%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-core",
    "version" : "6.4.13+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.4.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "04912edbd2d384bddd9ac4435b0fc292a4e6b901283a9f2a6b10128676da6675"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.4.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.4.13%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-crypto",
    "version" : "6.4.13+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.4.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4913e942527d4573a4be69467f65ead3a633631d68bf35db077e12da39d28794"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.4.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.security/spring-security-web@6.4.13%2Bbackpatch.001",
    "group" : "org.springframework.security",
    "name" : "spring-security-web",
    "version" : "6.4.13+backpatch.001",
    "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.4.13%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "3a591ecdc512df02e1c5ffc1680dcae883392f0887a15391e3849fdf0c9d0504"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-22732 onto the 6.4.13 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.ws/spring-ws-core@4.0.17%2Bbackpatch.001",
    "group" : "org.springframework.ws",
    "name" : "spring-ws-core",
    "version" : "4.0.17+backpatch.001",
    "purl" : "pkg:maven/org.springframework.ws/spring-ws-core@4.0.17%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "95cca428336771b058e2bd4a217d01b08d420d30bd012aafd1e530720d8256fb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40998 onto the 4.0.17 baseline.",
      "commits" : [ {
        "uid" : "eb8d66c099",
        "url" : "https://github.com/spring-projects/spring-ws/commit/eb8d66c099"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.springframework.ws/spring-xml@4.0.17%2Bbackpatch.001",
    "group" : "org.springframework.ws",
    "name" : "spring-xml",
    "version" : "4.0.17+backpatch.001",
    "purl" : "pkg:maven/org.springframework.ws/spring-xml@4.0.17%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7d554bfdb00523ae2841845376c2d60b36ac251fb32c2a420c087b3db3b94dee"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40998 onto the 4.0.17 baseline.",
      "commits" : [ {
        "uid" : "eb8d66c099",
        "url" : "https://github.com/spring-projects/spring-ws/commit/eb8d66c099"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-common@2.5.1%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-common",
    "version" : "2.5.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.5.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "50576494aceddbd4ccb306d7ab3a35f332e3a08dabe629e8c9cfdbf53b0a70ae"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.5.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-core@2.5.1%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-core",
    "version" : "2.5.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.5.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "79678edf69ae42e10dd27be98c495825658b381769e66712ca29550375b32440"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.5.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-common@2.6.0%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-common",
    "version" : "2.6.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.6.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "1abd2a036477575cb883be5f269b1a65136240f892de2b15925866b8dcda2b47"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.6.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-core@2.6.0%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-core",
    "version" : "2.6.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.6.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8c01236eab15bdaea1f004a50d8dc3e0fe1d567ac386cf19babf66f27c4ee3ec"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.6.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-common@2.7.0%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-common",
    "version" : "2.7.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.7.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ff3cacc339bef5cd888e40b7d76315b0f3d1a0d228e5ae2d591e721c9591f7dd"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.7.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-core@2.7.0%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-core",
    "version" : "2.7.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.7.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6d18b3e2ad33778f932e46b4bf098d1781b79eea9b52aa42de53f3bbbd6b9693"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.7.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-common@2.8.0%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-common",
    "version" : "2.8.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.8.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8c756497d0fe6352de8d09c4d79c6e026ed1ec3b70d2a0892cd9497c02dc87ab"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.8.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-core@2.8.0%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-core",
    "version" : "2.8.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.8.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "a76f79cd60a0bed1b290d648abd0038bac0628f36c9af7653f78f7b72e7b2841"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.8.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-common@2.9.1%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-common",
    "version" : "2.9.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.9.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6372631f3f5f2d6557c1e791a7ae33dfb926f771bdefd1bc9ba2b31e7ca9ef01"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.9.1 baseline.",
      "commits" : [ {
        "uid" : "5a8fe830b2a2308a2b24ac8115a391af477f64f5",
        "url" : "https://github.com/apache/mina-sshd/commit/5a8fe830b2a2308a2b24ac8115a391af477f64f5"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.sshd/sshd-core@2.9.1%2Bbackpatch.001",
    "group" : "org.apache.sshd",
    "name" : "sshd-core",
    "version" : "2.9.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.9.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "25ad7fb930d5711b121a67dd434d620517e5675c82523c03be8cdd31a78a527c"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2022-45047 onto the 2.9.1 baseline.",
      "commits" : [ {
        "uid" : "5a8fe830b2a2308a2b24ac8115a391af477f64f5",
        "url" : "https://github.com/apache/mina-sshd/commit/5a8fe830b2a2308a2b24ac8115a391af477f64f5"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001",
    "group" : "org.apache.struts",
    "name" : "struts-core",
    "version" : "1.3.10+backpatch.001",
    "purl" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f65c70fb109b33651f01cf551dcbc70fdd64c3db9e3aa982b2c32afc1097c325"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2016-1181, CVE-2016-1182, CVE-2015-0899 onto the 1.3.10 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001",
    "group" : "org.apache.struts",
    "name" : "struts2-core",
    "version" : "2.5.33+backpatch.001",
    "purl" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4fb8ac8566b7945207b45c6d80d0ae68fc3b3cadd98e45d27feca77fe23496cb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2024-53677, CVE-2025-66675, CVE-2025-64775, CVE-2025-68493 onto the 2.5.33 baseline.",
      "commits" : [ {
        "uid" : "831568929cfba700f790f6ebe6e335f9f33fb468",
        "url" : "https://github.com/apache/struts/commit/831568929cfba700f790f6ebe6e335f9f33fb468"
      }, {
        "uid" : "6658c6360",
        "url" : "https://github.com/apache/struts/commit/6658c6360"
      }, {
        "uid" : "d2d01dfe93add786a65b3fd5b13cacaa7be0d99b",
        "url" : "https://github.com/apache/struts/commit/d2d01dfe93add786a65b3fd5b13cacaa7be0d99b"
      }, {
        "uid" : "0bc0217b9de49545b8307a98d6ca2cce3a85390f",
        "url" : "https://github.com/apache/struts/commit/0bc0217b9de49545b8307a98d6ca2cce3a85390f"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.struts/struts2-core@2.3.37%2Bbackpatch.001",
    "group" : "org.apache.struts",
    "name" : "struts2-core",
    "version" : "2.3.37+backpatch.001",
    "purl" : "pkg:maven/org.apache.struts/struts2-core@2.3.37%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8b3b749f64ed109db2a220a756e81c1bda13dda7d75553fc509184e827db7e7b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-50164 onto the 2.3.37 baseline.",
      "commits" : [ {
        "uid" : "162e29fee9136f4bfd9b2376da2cbf590f9ea163",
        "url" : "https://github.com/apache/struts/commit/162e29fee9136f4bfd9b2376da2cbf590f9ea163"
      }, {
        "uid" : "d8c69691ef1d15e76a5f4fcf33039316da2340b6",
        "url" : "https://github.com/apache/struts/commit/d8c69691ef1d15e76a5f4fcf33039316da2340b6"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.001",
    "group" : "org.apache.tapestry",
    "name" : "tapestry-framework",
    "version" : "4.1.6+backpatch.001",
    "purl" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c0cf9cdc52c2f0ecf81f6dfbdac6f1769764e731bd652ef777b675e87aeef5a2"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-17531 onto the 4.1.6 baseline.",
      "commits" : [ {
        "uid" : "fdb3d7c970352a6692c769942dd9b2c81364b709",
        "url" : "https://github.com/apache/tapestry4/commit/fdb3d7c970352a6692c769942dd9b2c81364b709"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.002",
    "group" : "org.apache.tapestry",
    "name" : "tapestry-framework",
    "version" : "4.1.6+backpatch.002",
    "purl" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "58a60afe54de02a9f0327ce9480ee11c8a3253901b9189b02e003e0b99bcdf87"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-17531 onto the 4.1.6 baseline.",
      "commits" : [ {
        "uid" : "fdb3d7c970352a6692c769942dd9b2c81364b709",
        "url" : "https://github.com/apache/tapestry4/commit/fdb3d7c970352a6692c769942dd9b2c81364b709"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001",
    "group" : "org.apache.tapestry",
    "name" : "tapestry-core",
    "version" : "5.5.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "02eab9781d2e3ee8453625a2e97390e18bfec7bd2629409668694b2d6ed590b8"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-27850, CVE-2021-30638, CVE-2020-13953, CVE-2022-31781 onto the 5.5.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.thrift/libthrift@0.13.0%2Bbackpatch.001",
    "group" : "org.apache.thrift",
    "name" : "libthrift",
    "version" : "0.13.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.thrift/libthrift@0.13.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "511c847fdd6504757c92372c58a9f4497312b84d358d5a0288d3d5e93a10db3d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-43869 onto the 0.13.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001",
    "group" : "org.thymeleaf",
    "name" : "thymeleaf-spring5",
    "version" : "3.1.3.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "30116a419db832463fdb008f4171c24a0e7089d5e4ad1baf55f3032041776c37"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40478, CVE-2026-41901 onto the 3.1.3.RELEASE baseline.",
      "commits" : [ {
        "uid" : "76680a7200548fd26b9234e58a59d6b2ca46ebfa",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/76680a7200548fd26b9234e58a59d6b2ca46ebfa"
      }, {
        "uid" : "8af2373885970a7946b738d6f66d1f2a7e4fa799",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/8af2373885970a7946b738d6f66d1f2a7e4fa799"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001",
    "group" : "org.thymeleaf",
    "name" : "thymeleaf-spring6",
    "version" : "3.1.3.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "88695c5ebd4098b57a53d3ce6a4a5850108fc7c37a153d620cf6f3567530d7bc"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40478, CVE-2026-41901 onto the 3.1.3.RELEASE baseline.",
      "commits" : [ {
        "uid" : "76680a7200548fd26b9234e58a59d6b2ca46ebfa",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/76680a7200548fd26b9234e58a59d6b2ca46ebfa"
      }, {
        "uid" : "8af2373885970a7946b738d6f66d1f2a7e4fa799",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/8af2373885970a7946b738d6f66d1f2a7e4fa799"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001",
    "group" : "org.thymeleaf",
    "name" : "thymeleaf",
    "version" : "3.1.3.RELEASE+backpatch.001",
    "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c466ae64359cc298b22d26a266e81224b032547d6ec06b5da0830d7baa98fe18"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40478, CVE-2026-41901 onto the 3.1.3.RELEASE baseline.",
      "commits" : [ {
        "uid" : "76680a7200548fd26b9234e58a59d6b2ca46ebfa",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/76680a7200548fd26b9234e58a59d6b2ca46ebfa"
      }, {
        "uid" : "8af2373885970a7946b738d6f66d1f2a7e4fa799",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/8af2373885970a7946b738d6f66d1f2a7e4fa799"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002",
    "group" : "org.thymeleaf",
    "name" : "thymeleaf-spring5",
    "version" : "3.1.3.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c482f35011d0c6c49a218fb32491396d32f3bdff7165baba4ec0ff795ee758e9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40478, CVE-2026-41901, CVE-2026-40477 onto the 3.1.3.RELEASE baseline.",
      "commits" : [ {
        "uid" : "76680a7200548fd26b9234e58a59d6b2ca46ebfa",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/76680a7200548fd26b9234e58a59d6b2ca46ebfa"
      }, {
        "uid" : "8af2373885970a7946b738d6f66d1f2a7e4fa799",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/8af2373885970a7946b738d6f66d1f2a7e4fa799"
      }, {
        "uid" : "c115713f6d73a4c0e2d83b1fb9e385db4199fb2a",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/c115713f6d73a4c0e2d83b1fb9e385db4199fb2a"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002",
    "group" : "org.thymeleaf",
    "name" : "thymeleaf-spring6",
    "version" : "3.1.3.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "abb09be7090e7e6ec18b44897af82a4c897b4e600185bb41b4fcfd73cfa5f8c3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40478, CVE-2026-41901, CVE-2026-40477 onto the 3.1.3.RELEASE baseline.",
      "commits" : [ {
        "uid" : "76680a7200548fd26b9234e58a59d6b2ca46ebfa",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/76680a7200548fd26b9234e58a59d6b2ca46ebfa"
      }, {
        "uid" : "8af2373885970a7946b738d6f66d1f2a7e4fa799",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/8af2373885970a7946b738d6f66d1f2a7e4fa799"
      }, {
        "uid" : "c115713f6d73a4c0e2d83b1fb9e385db4199fb2a",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/c115713f6d73a4c0e2d83b1fb9e385db4199fb2a"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002",
    "group" : "org.thymeleaf",
    "name" : "thymeleaf",
    "version" : "3.1.3.RELEASE+backpatch.002",
    "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "47563f4ad1c0608e2421f8f0d531bfd5641736dde30756a3808add09b690c59a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-40478, CVE-2026-41901, CVE-2026-40477 onto the 3.1.3.RELEASE baseline.",
      "commits" : [ {
        "uid" : "76680a7200548fd26b9234e58a59d6b2ca46ebfa",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/76680a7200548fd26b9234e58a59d6b2ca46ebfa"
      }, {
        "uid" : "8af2373885970a7946b738d6f66d1f2a7e4fa799",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/8af2373885970a7946b738d6f66d1f2a7e4fa799"
      }, {
        "uid" : "c115713f6d73a4c0e2d83b1fb9e385db4199fb2a",
        "url" : "https://github.com/thymeleaf/thymeleaf/commit/c115713f6d73a4c0e2d83b1fb9e385db4199fb2a"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "1.28.5+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6c63c52c3593d386db3737e7483543efa2ddb931130505aa6d828baf1034799a"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516, CVE-2025-54988 onto the 1.28.5 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.1.0%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.1.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.1.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "00312b3f4f13abbbc375e8968d6fedb864b0320be947f00561a0f47ffd337af1"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.1.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.2.1%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.2.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.2.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4a7085a593943385179e14a9ae2a65d90d60536bd98b911e752e178458bbeec3"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.2.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.3.0%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.3.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.3.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "156bf228b81f627973fef40612e48cf9ea799c1ad08e2601e3c46799c4fe0b3b"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.3.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.4.1%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.4.1+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.4.1%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "df98e6e45bb79bd28543ad6c2beee5463f1a2e3d1486d9bf47ac0dd537561d46"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.4.1 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.5.0%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.5.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.5.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e024ee6703de1c9651d12a5dc7bb81516adef1f2f0069fd2702b8b2fc34f2809"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.5.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.6.0%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.6.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.6.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6090c5ab2dda1e5e2e86ca380a1ab7c9b52cfb11c9968b958b546c9b1e570b05"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.6.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.7.0%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.7.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.7.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "033139f7d0712087557a0106ccd1134b9458c5346a6954890d10eebc193581db"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.7.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.8.0%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.8.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.8.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "7ad631520cfafda317ca45a354e952967d2a93b8a49452decc311a7b9e9ab470"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516 onto the 2.8.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001",
    "group" : "org.apache.tika",
    "name" : "tika-core",
    "version" : "2.9.4+backpatch.001",
    "purl" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "56638e346f4be02b0d28cf8d1d2b4a4b7f3f940d6539eb4e826d72a5bf5563be"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66516, CVE-2025-54988 onto the 2.9.4 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tiles/tiles-api@3.0.8%2Bbackpatch.001",
    "group" : "org.apache.tiles",
    "name" : "tiles-api",
    "version" : "3.0.8+backpatch.001",
    "purl" : "pkg:maven/org.apache.tiles/tiles-api@3.0.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c7625623d2bbbf13fc7f7af695d654ddd4d82dca84aba296bec9efd99354b363"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-49735 onto the 3.0.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tiles/tiles-core@3.0.8%2Bbackpatch.001",
    "group" : "org.apache.tiles",
    "name" : "tiles-core",
    "version" : "3.0.8+backpatch.001",
    "purl" : "pkg:maven/org.apache.tiles/tiles-core@3.0.8%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "6e013428e1a581038d2a948a6d1bf77ada18ec2a8cbe0aab1949642fed88ac0d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2023-49735 onto the 3.0.8 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001",
    "group" : "org.apache.tomcat",
    "name" : "tomcat-catalina",
    "version" : "7.0.109+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "eb4b1d86940ad3da193e035d95f31f3710f75d26ba810947457ac295a23c5e80"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-43512, CVE-2026-43515 onto the 7.0.109 baseline.",
      "commits" : [ {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001",
    "group" : "org.apache.tomcat",
    "name" : "tomcat-catalina",
    "version" : "8.0.53+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8ec25ec95a53e010805ed2c72127fce59422cd791582ead8f5e2ee051895ebc6"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-43512, CVE-2026-43515 onto the 8.0.53 baseline.",
      "commits" : [ {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat80/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat80/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001",
    "group" : "org.apache.tomcat",
    "name" : "tomcat-catalina",
    "version" : "8.5.100+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "18bc2f1dba65b6b1c072d910921a912cfb619b154d8524e3feaf8e078722e639"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-43512, CVE-2026-43515 onto the 8.5.100 baseline.",
      "commits" : [ {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001",
    "group" : "org.apache.tomcat.embed",
    "name" : "tomcat-embed-core",
    "version" : "7.0.109+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "df30e019b2c118a617dae5f1685e4a109cb8a0699c3974154d48fb84997fb3fa"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-43512, CVE-2026-43515 onto the 7.0.109 baseline.",
      "commits" : [ {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001",
    "group" : "org.apache.tomcat.embed",
    "name" : "tomcat-embed-core",
    "version" : "8.0.53+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "beb1187cc841d30116eeaa9e4ec28d1f4750b537370e1ad99ba64114473ccd35"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-43512, CVE-2026-43515 onto the 8.0.53 baseline.",
      "commits" : [ {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat80/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat80/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
    "group" : "org.apache.tomcat.embed",
    "name" : "tomcat-embed-core",
    "version" : "8.0.53+backpatch.002",
    "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "c5e2f7c0569fb472c00d94490c3b47ebfee3db72712bafa1cff95b60bcf11076"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-1938, CVE-2026-43512, CVE-2026-43515 onto the 8.0.53 baseline.",
      "commits" : [ {
        "uid" : "b99fba5bd796d876ea536e83299603443842feba",
        "url" : "https://github.com/apache/tomcat80/commit/b99fba5bd796d876ea536e83299603443842feba"
      }, {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat80/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat80/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001",
    "group" : "org.apache.tomcat.embed",
    "name" : "tomcat-embed-core",
    "version" : "8.5.100+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66614, CVE-2026-32990 onto the 8.5.100 baseline.",
      "commits" : [ {
        "uid" : "152c14885d45f5e0a8b59bd9f93c289cfe20ce30",
        "url" : "https://github.com/apache/tomcat/commit/152c14885d45f5e0a8b59bd9f93c289cfe20ce30"
      }, {
        "uid" : "a4aa74232e826028cd2f7ba0445caf8a8b52c509",
        "url" : "https://github.com/apache/tomcat/commit/a4aa74232e826028cd2f7ba0445caf8a8b52c509"
      }, {
        "uid" : "9276b5e783c8cd5b3fe2bb716306b65004bdd940",
        "url" : "https://github.com/apache/tomcat/commit/9276b5e783c8cd5b3fe2bb716306b65004bdd940"
      }, {
        "uid" : "95f7778248cac46d03e6af04de9c72a598be3a53",
        "url" : "https://github.com/apache/tomcat/commit/95f7778248cac46d03e6af04de9c72a598be3a53"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002",
    "group" : "org.apache.tomcat.embed",
    "name" : "tomcat-embed-core",
    "version" : "8.5.100+backpatch.002",
    "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "4a225febfa55924ebb544d43ed6939b486870ed0ca379d3e6e231149f717b475"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-66614, CVE-2026-32990, CVE-2026-43512, CVE-2026-43515 onto the 8.5.100 baseline.",
      "commits" : [ {
        "uid" : "152c14885d45f5e0a8b59bd9f93c289cfe20ce30",
        "url" : "https://github.com/apache/tomcat/commit/152c14885d45f5e0a8b59bd9f93c289cfe20ce30"
      }, {
        "uid" : "a4aa74232e826028cd2f7ba0445caf8a8b52c509",
        "url" : "https://github.com/apache/tomcat/commit/a4aa74232e826028cd2f7ba0445caf8a8b52c509"
      }, {
        "uid" : "9276b5e783c8cd5b3fe2bb716306b65004bdd940",
        "url" : "https://github.com/apache/tomcat/commit/9276b5e783c8cd5b3fe2bb716306b65004bdd940"
      }, {
        "uid" : "95f7778248cac46d03e6af04de9c72a598be3a53",
        "url" : "https://github.com/apache/tomcat/commit/95f7778248cac46d03e6af04de9c72a598be3a53"
      }, {
        "uid" : "db919ff9912b4d61d1b702a1342b8bde39270031",
        "url" : "https://github.com/apache/tomcat/commit/db919ff9912b4d61d1b702a1342b8bde39270031"
      }, {
        "uid" : "6565a6cb6499e56fe2f34457cec99f9d1c4f39e9",
        "url" : "https://github.com/apache/tomcat/commit/6565a6cb6499e56fe2f34457cec99f9d1c4f39e9"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.tomcat/tomcat-tribes@7.0.109%2Bbackpatch.001",
    "group" : "org.apache.tomcat",
    "name" : "tomcat-tribes",
    "version" : "7.0.109+backpatch.001",
    "purl" : "pkg:maven/org.apache.tomcat/tomcat-tribes@7.0.109%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "06baa06f4af1eb25f61295e71c3d5948d84fce1198da06ceb886de1e5913cde9"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2026-29146 onto the 7.0.109 baseline.",
      "commits" : [ {
        "uid" : "0112ed22abfccc3d54e44d91eb08804d0886acd1",
        "url" : "https://github.com/apache/tomcat/commit/0112ed22abfccc3d54e44d91eb08804d0886acd1"
      }, {
        "uid" : "776e12b3e2b0b4507b8a3b62c187ceb0b74bf418",
        "url" : "https://github.com/apache/tomcat/commit/776e12b3e2b0b4507b8a3b62c187ceb0b74bf418"
      } ]
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/io.undertow/undertow-core@2.2.3.Final%2Bbackpatch.001",
    "group" : "io.undertow",
    "name" : "undertow-core",
    "version" : "2.2.3.Final+backpatch.001",
    "purl" : "pkg:maven/io.undertow/undertow-core@2.2.3.Final%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "f2b5ee1c3ced0f80281e17c2ae8f6ca363af9a24245ec30c78939b164320fc6d"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-3629 onto the 2.2.3.Final baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.velocity/velocity@1.7%2Bbackpatch.001",
    "group" : "org.apache.velocity",
    "name" : "velocity",
    "version" : "1.7+backpatch.001",
    "purl" : "pkg:maven/org.apache.velocity/velocity@1.7%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "91d7cff0f9214ad751c0a482bf4da922159b9d418620fa3515a567a14a06f7f0"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-13936 onto the 1.7 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.velocity/velocity-engine-core@2.2%2Bbackpatch.001",
    "group" : "org.apache.velocity",
    "name" : "velocity-engine-core",
    "version" : "2.2+backpatch.001",
    "purl" : "pkg:maven/org.apache.velocity/velocity-engine-core@2.2%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "e0319b83446502951b4bcde77938c3eca910f1990ee531d6f053f0cc42757bbc"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2020-13936 onto the 2.2 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001",
    "group" : "xerces",
    "name" : "xercesImpl",
    "version" : "2.11.0+backpatch.001",
    "purl" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "d672c963a3e7926f8a848721d667030404961dc971b269220226842aac0ea29e"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2012-0881, CVE-2013-4002, CVE-2022-23437 onto the 2.11.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.xmlbeans/xmlbeans@2.6.0%2Bbackpatch.001",
    "group" : "org.apache.xmlbeans",
    "name" : "xmlbeans",
    "version" : "2.6.0+backpatch.001",
    "purl" : "pkg:maven/org.apache.xmlbeans/xmlbeans@2.6.0%2Bbackpatch.001",
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-23926 onto the 2.6.0 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.santuario/xmlsec@2.1.4%2Bbackpatch.001",
    "group" : "org.apache.santuario",
    "name" : "xmlsec",
    "version" : "2.1.4+backpatch.001",
    "purl" : "pkg:maven/org.apache.santuario/xmlsec@2.1.4%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "34a9763ac9c66731b31f7d177fd68bb0c882c2710a4c5b3524fadd7d579070b4"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-40690 onto the 2.1.4 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/com.thoughtworks.xstream/xstream@1.4.17%2Bbackpatch.001",
    "group" : "com.thoughtworks.xstream",
    "name" : "xstream",
    "version" : "1.4.17+backpatch.001",
    "purl" : "pkg:maven/com.thoughtworks.xstream/xstream@1.4.17%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "82437b8bd37ed9a535804afef35289b9dcdab0f695a8a827bf2a6389cccff725"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2021-39144 onto the 1.4.17 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.001",
    "group" : "org.apache.struts.xwork",
    "name" : "xwork-core",
    "version" : "2.3.37+backpatch.001",
    "purl" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.001",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "ff9e3d073130c7828346373da3f9560c853f323aa2a5b53e75386d7441e550fb"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-68493 onto the 2.3.37 baseline."
    }
  }, {
    "type" : "library",
    "bom-ref" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.002",
    "group" : "org.apache.struts.xwork",
    "name" : "xwork-core",
    "version" : "2.3.37+backpatch.002",
    "purl" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.002",
    "hashes" : [ {
      "alg" : "SHA-256",
      "content" : "8ce5bac3d21cba3eaec11bffa17f31e27aa8c46d43343ec0740d2d9ad17d4a18"
    } ],
    "pedigree" : {
      "notes" : "Backport of the upstream fix(es) for CVE-2025-68493 onto the 2.3.37 baseline."
    }
  } ],
  "vulnerabilities" : [ {
    "id" : "CVE-2023-46604",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-46604"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-46604 fixed by backporting the upstream fix onto the 5.14.5 baseline. Fixed upstream in: 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3 / 6.0.0 (all terminal releases of already-EOL branches; nothing at 5.14.x or earlier); see component pedigree commit 3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.activemq/activemq-broker@5.14.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-46604",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-46604"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-46604 fixed by backporting the upstream fix onto the 5.14.5 baseline. Fixed upstream in: 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3 / 6.0.0 (all terminal releases of already-EOL branches; nothing at 5.14.x or earlier); see component pedigree commit 3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.activemq/activemq-client@5.14.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-46604",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-46604"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-46604 fixed by backporting the upstream fix onto the 5.14.5 baseline. Fixed upstream in: 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3 / 6.0.0 (all terminal releases of already-EOL branches; nothing at 5.14.x or earlier); see component pedigree commit 3eaf3107f4fb9a3ce7ab45c175bfaeac7e866d5b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.activemq/activemq-openwire-legacy@5.14.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-27446",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-27446"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-27446 fixed by backporting the upstream fix onto the 2.44.0 baseline. Fixed upstream in: 2.52.0, published as org.apache.artemis:artemis-server — org.apache.activemq:artemis-server:2.52.0 is a relocation POM with no jar; see component pedigree commit 521e672e4108675806d748158444ce23f9ef76ca."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.activemq/artemis-server@2.44.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47561",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47561"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47561 fixed by backporting the upstream fix onto the 1.11.3 baseline. Fixed upstream in: 1.11.4 / 1.12.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.avro/avro@1.11.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000338",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000338"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000338 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000341",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000341"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000341 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000342",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000342"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000342 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000343",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000343"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000343 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000344",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000344"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000344 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000352",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000352"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000352 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-26939",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-26939"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-26939 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.61."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000338",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000338"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000338 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-1000341",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000341"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000341 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-1000342",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000342"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000342 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2020-26939",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-26939"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-26939 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.61."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-1000343",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000343"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "1.47 rejects DSA strength > 1024 at the API boundary, so the >1024-with-160-bit-q pairing the CVE describes cannot be reached; the 1.47 and 1.56 defaults are identical (p=1024, q=160)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-1000344",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000344"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "1.47 registers only KDF2+HMAC IES via JCEIESCipher; the DHIESwithAES variant the 1.56 fix removes does not exist here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-1000352",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000352"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "1.47 registers only KDF2+HMAC ECIES via JCEIESCipher; the ECIESwithAES variant the 1.56 fix removes does not exist here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-1000338",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000338"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000338 fixed by backporting the upstream fix onto the 1.46 baseline. Fixed upstream in: 1.56 (on the -jdk15on coordinate only)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000342",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000342"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000342 fixed by backporting the upstream fix onto the 1.46 baseline. Fixed upstream in: 1.56 (on the -jdk15on coordinate only)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2018-20433",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2018-20433"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2018-20433 fixed by backporting the upstream fix onto the 0.9.5.2 baseline. Fixed upstream in: 0.9.5.3; see component pedigree commit 7dfdda63f42759a5ec9b63d725b7412f74adb3e1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.mchange/c3p0@0.9.5.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-39135",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-39135"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-39135 fixed by backporting the upstream fix onto the 1.29.0 baseline. Fixed upstream in: 1.32.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.calcite/calcite-core@1.29.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-39135",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-39135"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-39135 fixed by backporting the upstream fix onto the 1.30.0 baseline. Fixed upstream in: 1.32.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.calcite/calcite-core@1.30.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-39135",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-39135"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-39135 fixed by backporting the upstream fix onto the 1.31.0 baseline. Fixed upstream in: 1.32.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.calcite/calcite-core@1.31.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-11971",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-11971"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0; see component pedigree commit b954402272ddcfbb45dc1495520f920e70cc041c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-11971",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-11971"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0; see component pedigree commit b954402272ddcfbb45dc1495520f920e70cc041c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2020-11971",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-11971"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0; see component pedigree commit b954402272ddcfbb45dc1495520f920e70cc041c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.003"
    } ]
  }, {
    "id" : "CVE-2020-11971",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-11971"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0; see component pedigree commit b954402272ddcfbb45dc1495520f920e70cc041c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2025-48734",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-48734"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-48734 fixed by backporting the upstream fix onto the 1.9.4 baseline. Fixed upstream in: 1.11.0 (commit 28ad955a); also 2.0.0-M2 on the org.apache.commons:commons-beanutils2 coordinate; see component pedigree commit 28ad955a1613ed5885870cc7da52093c1ce739dc."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2014-0114",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2014-0114"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2014-0114 fixed by backporting the upstream fix onto the 1.9.2 baseline. Fixed upstream in: 1.9.4 (BEANUTILS-520, commit 62e82ad9)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-10086",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-10086"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-10086 fixed by backporting the upstream fix onto the 1.9.2 baseline. Fixed upstream in: 1.9.4 (same commit 62e82ad9 — the SUPPRESS_CLASS-by-default change)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-7501",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-7501"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2015-7501 fixed by backporting the upstream fix onto the 3.2.1 baseline. Fixed upstream in: 3.2.2 (COLLECTIONS-580); see component pedigree commit 1642b00d67b96de87cad44223efb9ab5b4fb7be5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-6420",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-6420"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2015-6420 fixed by backporting the upstream fix onto the 3.2.1 baseline. Fixed upstream in: 3.2.2 (COLLECTIONS-580)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-7501",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-7501"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2015-7501 fixed by backporting the upstream fix onto the 4.0 baseline. Fixed upstream in: 4.1 (COLLECTIONS-580) — NOT ported; see fix_description; see component pedigree commit e585cd0433ae4cfbc56e58572b9869bd0c86b611."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-6420",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-6420"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2015-6420 fixed by backporting the upstream fix onto the 4.0 baseline. Fixed upstream in: 4.1 (COLLECTIONS-580) — NOT ported; see fix_description."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-35515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-35515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-35515 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21; see component pedigree commit 3fe6b42110dc56d0d6fe0aaf80cfecb8feea5321."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-35516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-35516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-35516 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21; see component pedigree commit 41359f56e62d41ed59493cdcbaa5d52d0f89fbb9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-35517",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-35517"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-35517 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21; see component pedigree commit 004e87375572d459ff51c19fe35aa83685cc0cd0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-36090",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-36090"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-36090 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21; see component pedigree commit 5c5f8a89e91b95c0ba984549b5804289f55b8200."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-1953",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-1953"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-1953 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-33980",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-33980"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-33980 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.8.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-33980",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-33980"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-33980 fixed by backporting the upstream fix onto the 2.7 baseline. Fixed upstream in: 2.8.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-1953",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-1953"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-1953 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-33980",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-33980"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-33980 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.8.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1000031",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1000031"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1000031 fixed by backporting the upstream fix onto the 1.3.1 baseline. Fixed upstream in: 1.3.3; see component pedigree commit 388e824518697c2c8f9f83fd964621d9c2f8fc4c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-3092",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-3092"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-3092 fixed by backporting the upstream fix onto the 1.3.1 baseline. Fixed upstream in: 1.3.2; see component pedigree commit d7a7b613373789fa6c3015457f1a15c7c5efd84d."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-24998",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-24998"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-24998 fixed by backporting the upstream fix onto the 1.3.1 baseline. Fixed upstream in: 1.5; see component pedigree commit e20c04990f7420ca917e96a84cec58b13a1b3d17."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2012-5783",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2012-5783"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2012-5783 fixed by a patch applied onto the 3.1 baseline; no upstream release carries this fix. Upstream status: none released (svn r1422573)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-httpclient/commons-httpclient@3.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.0.1 baseline. Fixed upstream in: 2.7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.0.1 baseline. Fixed upstream in: 2.14.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.1 baseline. Fixed upstream in: 2.7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.1 baseline. Fixed upstream in: 2.14.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.2 baseline. Fixed upstream in: 2.7; see component pedigree commit 2736b6fe0b3fa22ec8e2b4184897ecadb021fc78."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.2 baseline. Fixed upstream in: 2.14.0; see component pedigree commit rel/commons-io-2.14.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.3 baseline. Fixed upstream in: 2.7; see component pedigree commit 2736b6fe0b3fa22ec8e2b4184897ecadb021fc78."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.3 baseline. Fixed upstream in: 2.14.0; see component pedigree commit rel/commons-io-2.14.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.4 baseline. Fixed upstream in: 2.7; see component pedigree commit 2736b6fe0b3fa22ec8e2b4184897ecadb021fc78."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.4 baseline. Fixed upstream in: 2.14.0; see component pedigree commit rel/commons-io-2.14.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.7; see component pedigree commit 2736b6fe0b3fa22ec8e2b4184897ecadb021fc78."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.14.0; see component pedigree commit rel/commons-io-2.14.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.7; see component pedigree commit 2736b6fe0b3fa22ec8e2b4184897ecadb021fc78."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.14.0; see component pedigree commit 06fde31494c279ad940149e1a3d4944040c73c0d."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-29425",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-29425"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.7; see component pedigree commit 2736b6fe0b3fa22ec8e2b4184897ecadb021fc78."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-47554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-47554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.14.0; see component pedigree commit 06fde31494c279ad940149e1a3d4944040c73c0d."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002"
    } ]
  }, {
    "id" : "XRAY-125253",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/XRAY-125253"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "XRAY-125253 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.8.0; see component pedigree commit 97ae01c95837f50a2e9be34c370b271c4d8fc88b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-48924",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-48924"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-48924 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: org.apache.commons:commons-lang3 3.18.0 (a DIFFERENT coordinate). NOT fixed in the legacy commons-lang:commons-lang 2.x line, which is EOL at 2.6 (none); see component pedigree commit b424803abdb2bec818e4fbcb251ce031c22aca53."
    },
    "affects" : [ {
      "ref" : "pkg:maven/commons-lang/commons-lang@2.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-42889",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-42889"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-42889 fixed by backporting the upstream fix onto the 1.9 baseline. Fixed upstream in: 1.10.0; see component pedigree commit b9b40b903e2d1f9935039803c9852439576780ea."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.commons/commons-text@1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-46364",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-46364"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-46364 fixed by backporting the upstream fix onto the 3.3.13 baseline. Fixed upstream in: 3.4.10 / 3.5.5 — no 3.3.x line fix; see component pedigree commit bff4eb1959ecac3ddd5e824550497ef137479e26."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-46363",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-46363"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-46363 fixed by backporting the upstream fix onto the 3.3.13 baseline. Fixed upstream in: 3.4.10 / 3.5.5 — no 3.3.x line fix; see component pedigree commit a1b5578cf9175f27793a7fc0a9070f92aab5d2d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-46364",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-46364"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-46364 fixed by backporting the upstream fix onto the 3.3.13 baseline. Fixed upstream in: 3.4.10 / 3.5.5 — no 3.3.x line fix; see component pedigree commit bff4eb1959ecac3ddd5e824550497ef137479e26."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-46363",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-46363"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-46363 fixed by backporting the upstream fix onto the 3.3.13 baseline. Fixed upstream in: 3.4.10 / 3.5.5 — no 3.3.x line fix; see component pedigree commit a1b5578cf9175f27793a7fc0a9070f92aab5d2d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-48913",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-48913"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-48913 fixed by backporting the upstream fix onto the 3.5.11 baseline. Fixed upstream in: 3.6.8 / 4.0.9 / 4.1.3 (different minor/major lines; no 3.5.12 exists); see component pedigree commit b22a80b341bf7e24d2df6cb95a6e01e78d3ff7aa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.cxf/cxf-core@3.5.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-48913",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-48913"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-48913 fixed by backporting the upstream fix onto the 3.5.11 baseline. Fixed upstream in: 3.6.8 / 4.0.9 / 4.1.3 (different minor/major lines; no 3.5.12 exists); see component pedigree commit b22a80b341bf7e24d2df6cb95a6e01e78d3ff7aa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.cxf/cxf-rt-transports-jms@3.5.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-10683",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-10683"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-10683 fixed by backporting the upstream fix onto the 1.6.1 baseline. Fixed upstream in: org.dom4j:dom4j 2.0.3 / 2.1.3 (different groupId — NVD/GHSA treat them as distinct package identities); see component pedigree commit a8228522a99a02146106672a34c104adbda5c658."
    },
    "affects" : [ {
      "ref" : "pkg:maven/dom4j/dom4j@1.6.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-23457",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-23457"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-23457 fixed by backporting the upstream fix onto the 2.2.3.1 baseline. Fixed upstream in: 2.3.0.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.owasp.esapi/esapi@2.2.3.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-25845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25845 fixed by backporting the upstream fix onto the 1.2.68 baseline. Fixed upstream in: 1.2.83."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-25845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25845 fixed by backporting the upstream fix onto the 1.2.68 baseline. Fixed upstream in: 1.2.83."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-40094",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-40094"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-40094 fixed by backporting the upstream fix onto the 18.7 baseline. Fixed upstream in: 19.11, 20.9, 21.5, 22.0+ (same com.graphql-java:graphql-java coordinate, but only in newer lines; no 18.x fix — 18.x is EOL); see component pedigree commit 97743bc1b5caa2b0bd894dc8e128b47e4d771e4a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.graphql-java/graphql-java@18.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-25647",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25647"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25647 fixed by backporting the upstream fix onto the 2.8.8 baseline. Fixed upstream in: 2.8.9; see component pedigree commit 4906461db7dff60889ead0c03b84b3fc6aea150a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.code.gson/gson@2.8.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2018-10237",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2018-10237"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2018-10237 fixed by backporting the upstream fix onto the 20.0 baseline. Fixed upstream in: 24.1.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-2976",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-2976"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-2976 fixed by backporting the upstream fix onto the 20.0 baseline. Fixed upstream in: 32.0.0-jre."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-8908",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-8908"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-8908 fixed by backporting the upstream fix onto the 20.0 baseline. Fixed upstream in: 32.0.0-jre."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-2976",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-2976"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-2976 fixed by backporting the upstream fix onto the 31.1-jre baseline. Fixed upstream in: 32.0.0-jre; see component pedigree commit fdbf77d3f2b826fc0a70b1f9b9994b140ddf3bd8."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-8908",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-8908"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-8908 fixed by backporting the upstream fix onto the 31.1-jre baseline. Fixed upstream in: 32.0.0-jre."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-42392",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-42392"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-42392 fixed by backporting the upstream fix onto the 1.4.200 baseline. Fixed upstream in: 2.0.206; see component pedigree commit 956c6241868332c5b440f5d55ea8fdc1e51ae4fd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-42392",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-42392"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-42392 fixed by backporting the upstream fix onto the 1.4.200 baseline. Fixed upstream in: 2.0.206; see component pedigree commit 956c6241868332c5b440f5d55ea8fdc1e51ae4fd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2021-23463",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-23463"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-23463 fixed by backporting the upstream fix onto the 1.4.200 baseline. Fixed upstream in: 2.0.202; see component pedigree commit d83285fd2e48fb075780ee95badee6f5a15ea7f8."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2022-25168",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25168"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-25168",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25168"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2022-25168",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25168"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.003"
    } ]
  }, {
    "id" : "CVE-2022-25168",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25168"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2022-25168",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25168"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.8.5 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-25168",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-25168"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.8.5 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-10750",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-10750"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-10750 fixed by backporting the upstream fix onto the 3.10.6 baseline. Fixed upstream in: 3.11 (commit 5a47697519 — JavaSerializationFilterConfig class-filter feature)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-10750",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-10750"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-10750 fixed by backporting the upstream fix onto the 3.10.6 baseline. Fixed upstream in: 3.11 (commit 5a47697519 — JavaSerializationFilterConfig class-filter feature)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-0603",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-0603"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-0603 fixed by backporting the upstream fix onto the 5.4.33.Final baseline. Fixed upstream in: 5.3.38.Final (5.3 maintenance branch) and Hibernate 6.x. NOT fixed on the 5.6 line — no 5.6.16 was released. GHSA-2p5w-cvg5-gc5c lists affected >=5.2.8 <=5.6.15 with 'patched: None' and no commit link."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.hibernate/hibernate-core@5.4.33.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-0603",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-0603"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-0603 fixed by backporting the upstream fix onto the 5.5.9.Final baseline. Fixed upstream in: 5.3.38.Final (5.3 maintenance branch) and Hibernate 6.x. NOT fixed on the 5.6 line — no 5.6.16 was released. GHSA-2p5w-cvg5-gc5c lists affected >=5.2.8 <=5.6.15 with 'patched: None' and no commit link."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.hibernate/hibernate-core@5.5.9.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-0603",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-0603"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-0603 fixed by backporting the upstream fix onto the 5.6.15.Final baseline. Fixed upstream in: 5.3.38.Final (5.3 maintenance branch) and Hibernate 6.x. NOT fixed on the 5.6 line — no 5.6.16 was released. GHSA-2p5w-cvg5-gc5c lists affected >=5.2.8 <=5.6.15 with 'patched: None' and no commit link; see component pedigree commit 3f820fdf16ee4d1f556bc73b259625416d703048."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.hibernate/hibernate-core@5.6.15.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-27820",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-27820"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-27820 fixed by backporting the upstream fix onto the 5.4.1 baseline. Fixed upstream in: 5.4.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-9096",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-9096"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-9096 fixed by a patch applied onto the 2.1.7 baseline; no upstream release carries this fix. Upstream status: none. iText Group fixed it in com.itextpdf:itextpdf 5.5.12 / itext7 7.0.3, which is a different groupId AND an AGPL relicense, so it cannot be used in an MPL/LGPL artifact. Nothing on the com.lowagie:itext coordinate, and nothing in itext/itextpdf history, ever fixed it; see component pedigree commit aa4ac5f081150a80cc2f88b3bee50c68d57b29f7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.lowagie/itext@2.1.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.10.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.10.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-42003",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-42003"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-42003 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.12.7.1 / 2.13.4.2 — no 2.10.x line fix."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-42004",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-42004"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-42004 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.12.7.1 / 2.13.4 — no 2.10.x line fix; see component pedigree commit 7c0a74ee77a0896e9a3fde3600066ea0b7490f5b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-46877",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-46877"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-46877 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.12.6 / 2.13.1 — no 2.10.x line fix; see component pedigree commit 3ccde7d938fea547e598fdefe9a82cff37fed5cb."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.11.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.11.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.11.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.11.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.12.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.12.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.12.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.12.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.13.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.13.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-50193",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-50193"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-50193 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.14.0 — no 2.13.x line fix; see component pedigree commit 7814533c845b05e3cf511a6c638761fe2cef0613."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.13.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.13.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.14.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.14.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.14.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.14.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.15.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.15.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.15.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.15.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.16.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.16.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.16.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.16.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.17.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.17.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.17.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.17.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.19.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.19.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.19.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.19.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.20.x line fix; see component pedigree commit 434d6c511de7fdd9872f29157aafb6162d12d8d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54513",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.20.x line fix; see component pedigree commit 01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54514",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54514"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.20.x line fix; see component pedigree commit 2339bd43108a6dc8a0755dca91f03c599d7970f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-54515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-54515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.20.x line fix; see component pedigree commit bc1613c765704703ec7385e314fa8b19448e1ddd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-36518",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-36518"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-36518 fixed by backporting the upstream fix onto the 2.9.10.8 baseline. Fixed upstream in: 2.12.6.1 / 2.13.2.1 / 2.14.0 (no 2.9.x line fix — 2.9 was EOL); see component pedigree commit 83b928dab9ba6ef81cf48987fcd12071e1ddb0c9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.10.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-10202",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-10202"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-10202 fixed by a patch applied onto the 1.9.13 baseline; no upstream release carries this fix. Upstream status: none — fixed in the FasterXML/jackson-1 master tree (9ac68db8, Dec 2017) but never released to Central; 1.9.13 (Jul 2013) is the last and final 1.x release."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-10172",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-10172"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-10172 fixed by a patch applied onto the 1.9.13 baseline; no upstream release carries this fix. Upstream status: none — fixed in the FasterXML/jackson-1 master tree (54c6bc36, 2361ec46, Jul 2016) but never released to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-10202",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-10202"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-10202 fixed by a patch applied onto the 1.9.13 baseline; no upstream release carries this fix. Upstream status: none — fixed in the FasterXML/jackson-1 master tree (9ac68db8, Dec 2017) but never released to Central; 1.9.13 (Jul 2013) is the last and final 1.x release."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-10172",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-10172"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-10172 fixed by a patch applied onto the 1.9.13 baseline; no upstream release carries this fix. Upstream status: none — fixed in the FasterXML/jackson-1 master tree (54c6bc36, 2361ec46, Jul 2016) but never released to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-10492",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-10492"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-10492 fixed by backporting the upstream fix onto the 6.21.5 baseline. Fixed upstream in: 7.0.4."
    },
    "affects" : [ {
      "ref" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-6009",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-6009"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-6009 fixed by backporting the upstream fix onto the 6.21.5 baseline. Fixed upstream in: 7.0.7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.2.10.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.2.10.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-33813",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-33813"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-33813 fixed by a patch applied onto the 1.1.3 baseline; no upstream release carries this fix. Upstream status: none for org.jdom:jdom — upstream fixed it only on the org.jdom:jdom2 coordinate, in 2.0.6.1 (2021-10). 1.1.3 (2012-02) is the last and final 1.x release."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.jdom/jdom@1.1.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-8184",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-8184"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-8184 fixed by backporting the upstream fix onto the 9.3.30.v20211001 baseline. Fixed upstream in: 9.4.56.v20240826 / 10.0.24 / 11.0.24 / 12.0.9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-26048",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-26048"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-26048 fixed by backporting the upstream fix onto the 9.3.30.v20211001 baseline. Fixed upstream in: 9.4.51.v20230217 / 10.0.14 / 11.0.14."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-2332",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-2332"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-2332 fixed by backporting the upstream fix onto the 9.4.58.v20250814 baseline. Fixed upstream in: 12.0.33 / 12.1.7 (public). 9.4.60/10.0.28/11.0.28 are Webtide commercial-only and never shipped to Maven Central; 9.4.60 has no upstream git tag and 404s on Central; see component pedigree commit ff9eb742492d6dc3191bcd49668b1bce1e620d57."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.4.58.v20250814%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.0.2.v20100331 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.0.2.v20100331 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.0.2.v20100331 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.0.2.v20100331 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.1.6.v20100715 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.1.6.v20100715 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.1.6.v20100715 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.1.6.v20100715 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.2.2.v20101205 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.2.2.v20101205 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.2.2.v20101205 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.2.2.v20101205 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.3.1.v20110307 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.3.1.v20110307 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.3.1.v20110307 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.3.1.v20110307 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.4.5.v20110725 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.4.5.v20110725 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.4.5.v20110725 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.4.5.v20110725 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.5.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.5.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.5.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.5.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.6.21.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.6.21.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.6.21.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.6.21.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.0.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.0.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.0.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.0.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.1.22.v20160922 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.1.22.v20160922 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.1.22.v20160922 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.1.22.v20160922 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.2.0.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.2.0.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.2.0.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.2.0.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7656",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7656"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7656 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-2080",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-2080"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "All 33 BadMessage sites at 9.0.7 pass a bare status or a compile-time constant; the buffer-carrying message JetLeak leaks arrived in 9.2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7656",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7656"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7656 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-2080",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-2080"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "All 33 BadMessage sites at 9.0.7 pass a bare status or a compile-time constant; the buffer-carrying message JetLeak leaks arrived in 9.2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7656",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7656"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7656 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-2080",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-2080"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "All 28 BadMessage sites at 9.1.6 pass a bare status or a compile-time constant; the buffer-carrying message JetLeak leaks arrived in 9.2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7657",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7657"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7658",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7658"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2017-7656",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2017-7656"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2017-7656 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-2080",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-2080"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "All 28 BadMessage sites at 9.1.6 pass a bare status or a compile-time constant; the buffer-carrying message JetLeak leaks arrived in 9.2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2018-21234",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2018-21234"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2018-21234 fixed by backporting the upstream fix onto the 5.0.3 baseline. Fixed upstream in: 5.0.4; see component pedigree commit 9bffc3913aeb8472c11bb543243004b4b4376f16."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2018-21234",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2018-21234"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2018-21234 fixed by backporting the upstream fix onto the 5.0.3 baseline. Fixed upstream in: 5.0.4; see component pedigree commit 9bffc3913aeb8472c11bb543243004b4b4376f16."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2023-1370",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-1370"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-1370 fixed by backporting the upstream fix onto the 1.3.3 baseline. Fixed upstream in: 2.4.9 (2.x line only; 1.x never fixed); see component pedigree commit 5b3205d051952d3100aa0db1535f6ba6226bd87a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/net.minidev/json-smart@1.3.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-35554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-35554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-35554 fixed by backporting the upstream fix onto the 2.8.2 baseline. Fixed upstream in: 3.9.2 (also 4.0.2 / 4.1.2 / 4.2.0) — nothing was ever released on the 2.x line."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.kafka/kafka-clients@2.8.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-27817",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-27817"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-27817 fixed by backporting the upstream fix onto the 3.2.3 baseline. Fixed upstream in: 3.9.1 (also 4.0.0); see component pedigree commit 35829fddcbcf375eb0462d07a51bf8becb1b8757."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.2.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-35554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-35554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-35554 fixed by backporting the upstream fix onto the 3.8.1 baseline. Fixed upstream in: 3.9.2 (also 4.0.2 / 4.1.2 / 4.2.0); see component pedigree commit 1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-35554",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-35554"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-35554 fixed by backporting the upstream fix onto the 3.8.1 baseline. Fixed upstream in: 3.9.2 (also 4.0.2 / 4.1.2 / 4.2.0); see component pedigree commit 1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-27818",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-27818"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-27818 fixed by backporting the upstream fix onto the 3.8.1 baseline. Fixed upstream in: 3.9.1 (also 4.0.0); see component pedigree commit 8262e2315dacdf0c385ca7e1e28790f130f37bf1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-17571",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-17571"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-17571 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.0 (ch.qos.reload4j — different coordinate; never shipped as log4j:log4j); see component pedigree commit 6051245a6243c1d1375f99ba29013f7ce877cc9f."
    },
    "affects" : [ {
      "ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-23305",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-23305"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-23305 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.2 (removed in .18.1, restored via PreparedStatement in .18.2); see component pedigree commit e845f28e7fb0ecbc0fcce383b11179f2650a51a2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-23302",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-23302"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-23302 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.1; see component pedigree commit f221f2427c45134cf5768f46279ddf72fe1407c9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-4104",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-4104"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-4104 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.0; see component pedigree commit fb7b1ff1c8beb8544933248d00a46e9e30547e87."
    },
    "affects" : [ {
      "ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-23307",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-23307"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-23307 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.1; see component pedigree commit 64902fe18ce5a5dd40487051a2f6231d9fbbe9b0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-26464",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-26464"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-26464 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.25 (issue 53 — confirm the issue-53↔CVE-2023-26464 mapping before asserting scanner coverage); see component pedigree commit 3a86b8e5b474cdda25a255c0d8ba3ad427f7ff58."
    },
    "affects" : [ {
      "ref" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-44228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-44228 fixed by backporting the upstream fix onto the 2.14.1 baseline. Fixed upstream in: 2.15.0 (message lookups off) / completed in 2.16.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-45046",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-45046"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-45046 fixed by backporting the upstream fix onto the 2.14.1 baseline. Fixed upstream in: 2.16.0; see component pedigree commit c362aff473e9812798ff8f25f30a2619996605d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-45105",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-45105"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-45105 fixed by backporting the upstream fix onto the 2.14.1 baseline. Fixed upstream in: 2.17.0; see component pedigree commit 806023265f8c905b2dd1d81fd2458f64b2ea0b5e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-12801",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-12801"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-12801 fixed by backporting the upstream fix onto the 1.1.11 baseline. Fixed upstream in: 1.3.15 / 1.5.13."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-11226",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-11226"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-11226 fixed by backporting the upstream fix onto the 1.1.11 baseline. Fixed upstream in: 1.3.16 / 1.5.19."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-12801",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-12801"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-12801 fixed by backporting the upstream fix onto the 1.1.11 baseline. Fixed upstream in: 1.3.15 / 1.5.13."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-11226",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-11226"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-11226 fixed by backporting the upstream fix onto the 1.1.11 baseline. Fixed upstream in: 1.3.16 / 1.5.19."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-12801",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-12801"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-12801 fixed by backporting the upstream fix onto the 1.2.13 baseline. Fixed upstream in: 1.3.15 / 1.5.13."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-11226",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-11226"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-11226 fixed by backporting the upstream fix onto the 1.2.13 baseline. Fixed upstream in: 1.3.16 / 1.5.19."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-12801",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-12801"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-12801 fixed by backporting the upstream fix onto the 1.2.13 baseline. Fixed upstream in: 1.3.15 / 1.5.13."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-11226",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-11226"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-11226 fixed by backporting the upstream fix onto the 1.2.13 baseline. Fixed upstream in: 1.3.16 / 1.5.19."
    },
    "affects" : [ {
      "ref" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-52046",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-52046"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-52046 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.27, 2.1.10, 2.2.4."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-52046",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-52046"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-52046 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.27, 2.1.10, 2.2.4."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41409",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41409"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41409 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.28 / 2.1.11 / 2.2.6."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41635",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41635"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41635 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.28 / 2.1.11 / 2.2.6."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-47065",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-47065"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-47065 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.29 / 2.1.13 / 2.2.8."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.44."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-7238",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-7238"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2020-7238",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-7238"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003"
    } ]
  }, {
    "id" : "CVE-2020-7238",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-7238"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.42.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2021-43797",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-43797"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.71.Final."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2019-20445",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20445"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2020-7238",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-7238"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final; see component pedigree commit 39cafcb05c99f2aa9fce7e6597664c9ed6a63a95."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final; see component pedigree commit a7c18d44b46e02dadfe3da225a06e5091f5f328e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final; see component pedigree commit 39cafcb05c99f2aa9fce7e6597664c9ed6a63a95."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final; see component pedigree commit a7c18d44b46e02dadfe3da225a06e5091f5f328e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final; see component pedigree commit 39cafcb05c99f2aa9fce7e6597664c9ed6a63a95."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final; see component pedigree commit a7c18d44b46e02dadfe3da225a06e5091f5f328e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final; see component pedigree commit 39cafcb05c99f2aa9fce7e6597664c9ed6a63a95."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final; see component pedigree commit a7c18d44b46e02dadfe3da225a06e5091f5f328e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final; see component pedigree commit 39cafcb05c99f2aa9fce7e6597664c9ed6a63a95."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final; see component pedigree commit a7c18d44b46e02dadfe3da225a06e5091f5f328e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-16869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-16869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final; see component pedigree commit 39cafcb05c99f2aa9fce7e6597664c9ed6a63a95."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-20444",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-20444"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final; see component pedigree commit a7c18d44b46e02dadfe3da225a06e5091f5f328e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2021-0341",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-0341"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-0341 fixed by backporting the upstream fix onto the 3.14.9 baseline. Fixed upstream in: 4.9.2 (Kotlin 4.x line only — no 3.x release ever carried the fix); see component pedigree commit f574ea2f5259d9040f264ddeb582fb1ce563f10c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.squareup.okhttp3/okhttp@3.14.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.0.2 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.0.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.1.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.1.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.2.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.2.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.3.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.3.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.4.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.4.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.5.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.6.1 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.6.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.7.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.7.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.8.3 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.8.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.9.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0); see component pedigree commit e6a3fbc762b02c7950b1a76457aa4f5c062ef034."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-25581",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-25581"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.9.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0); see component pedigree commit e6a3fbc762b02c7950b1a76457aa4f5c062ef034."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2021-44228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-44228 fixed by backporting the upstream fix onto the 1.8.7 baseline. Fixed upstream in: 1.9.2 / 1.10.8 / 1.11.10 / 2.0.11."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-45046",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-45046"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-45046 fixed by backporting the upstream fix onto the 1.8.7 baseline. Fixed upstream in: 1.9.2 / 1.10.8 / 1.11.11 / 2.0.12; see component pedigree commit c362aff473e9812798ff8f25f30a2619996605d5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-45105",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-45105"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-45105 fixed by backporting the upstream fix onto the 1.8.7 baseline. Fixed upstream in: 1.9.2 / 1.10.9 / 1.11.12 / 2.0.13; see component pedigree commit 806023265f8c905b2dd1d81fd2458f64b2ea0b5e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-12415",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-12415"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-12415 fixed by backporting the upstream fix onto the 3.17 baseline. Fixed upstream in: 4.1.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.poi/poi-ooxml@3.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-1597",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-1597"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-1597 fixed by backporting the upstream fix onto the 42.4.0 baseline. Fixed upstream in: 42.4.4 (also 42.2.28 / 42.3.9 / 42.5.5 / 42.6.1 / 42.7.2)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31197",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31197"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31197 fixed by backporting the upstream fix onto the 42.4.0 baseline. Fixed upstream in: 42.4.1 (also 42.2.26 / 42.3.7)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-1597",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-1597"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-1597 fixed by backporting the upstream fix onto the 9.4.1212.jre7 baseline. Fixed upstream in: 42.4.4 (also 42.2.28 / 42.3.9 / 42.5.5 / 42.6.1 / 42.7.2) — every one of them a Java 8 release, which is why this baseline's consumers cannot take it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.postgresql/postgresql@9.4.1212.jre7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-7254",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-7254"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 2.4.1 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 2.x line was never patched — no fix exists on the baseline series; see component pedigree commit 4728531c162f2f9e8c2ca1add713cfee2db6be3b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.protobuf/protobuf-java@2.4.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-7254",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-7254"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 2.5.0 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 2.x line was never patched — no fix exists on the baseline series; see component pedigree commit 4728531c162f2f9e8c2ca1add713cfee2db6be3b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.protobuf/protobuf-java@2.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-7254",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-7254"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 2.6.1 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 2.x line was never patched — no fix exists on the baseline series; see component pedigree commit 4728531c162f2f9e8c2ca1add713cfee2db6be3b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.protobuf/protobuf-java@2.6.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-7254",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-7254"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 3.19.6 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 3.19.x line was never patched — no fix exists on the baseline series; see component pedigree commit 4728531c162f2f9e8c2ca1add713cfee2db6be3b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-7254",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-7254"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 3.19.6 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 3.19.x line was never patched — no fix exists on the baseline series; see component pedigree commit 4728531c162f2f9e8c2ca1add713cfee2db6be3b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2019-13990",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-13990"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-13990 fixed by backporting the upstream fix onto the 2.3.1 baseline. Fixed upstream in: 2.3.2; see component pedigree commit a1395ba118df306c7fe67c24fb0c9a95a4473140."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.quartz-scheduler/quartz@2.3.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-34062",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-34062"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-34062 fixed by backporting the upstream fix onto the 1.0.19 baseline. Fixed upstream in: 1.0.39 and 1.1.13 (NVD). NOTE: the analyst hint's '1.0.24 / 1.1.0' is INCORRECT — verified against NVD and the actual fix commit, which is an ancestor of v1.0.39 (not v1.0.24); see component pedigree commit 780e487ddc99edef1f9cf7720db8eae2ba671da7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.projectreactor.netty/reactor-netty-core@1.0.19%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-34062",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-34062"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-34062 fixed by backporting the upstream fix onto the 1.0.19 baseline. Fixed upstream in: 1.0.39 and 1.1.13 (NVD). NOTE: the analyst hint's '1.0.24 / 1.1.0' is INCORRECT — verified against NVD and the actual fix commit, which is an ancestor of v1.0.39 (not v1.0.24); see component pedigree commit 780e487ddc99edef1f9cf7720db8eae2ba671da7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.projectreactor.netty/reactor-netty-http@1.0.19%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-1471",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-1471"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-1471 fixed by backporting the upstream fix onto the 1.33 baseline. Fixed upstream in: 2.0 (secure-by-default via TagInspector; no fix on the 1.x line); see component pedigree commit 59ddbb3304bb8e22e2004d74cddaf9ed4086632e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.yaml/snakeyaml@1.33%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22022",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22022"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22022 fixed by backporting the upstream fix onto the 8.11.4 baseline. Fixed upstream in: 9.10.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.solr/solr-core@8.11.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-22946",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-22946"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-22946 fixed by backporting the upstream fix onto the 2.4.8 baseline. Fixed upstream in: 3.4.0 — no 2.4.x line fix; see component pedigree commit 909da96e1471886a01a9e1def93630c4fd40e74a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-54920",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-54920"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-54920 fixed by backporting the upstream fix onto the 2.4.8 baseline. Fixed upstream in: 3.5.7 — no 2.4.x line fix; see component pedigree commit a53a9c4d77377af9fbd648a8d9b528754d657aea."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-22946",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-22946"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-22946 fixed by backporting the upstream fix onto the 3.0.3 baseline. Fixed upstream in: 3.4.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-54920",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-54920"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-54920 fixed by backporting the upstream fix onto the 3.0.3 baseline. Fixed upstream in: 3.5.7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-27772",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-27772"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-27772 fixed by backporting the upstream fix onto the 1.5.22.RELEASE baseline. Fixed upstream in: 2.2.11.RELEASE — the 1.5 line was EOL a year before the fix landed (667ccdae84, 2020-10-13)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-20883",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-20883"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-20883 fixed by backporting the upstream fix onto the 1.5.22.RELEASE baseline. Fixed upstream in: 2.5.15 / 2.6.15 / 2.7.12 / 3.0.7 — the CVE record names 2.5.14 and earlier as affected, which includes this baseline."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-27772",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-27772"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-27772 fixed by backporting the upstream fix onto the 1.5.22.RELEASE baseline. Fixed upstream in: 2.2.11.RELEASE — the 1.5 line was EOL a year before the fix landed (667ccdae84, 2020-10-13)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-20883",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-20883"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-20883 fixed by backporting the upstream fix onto the 1.5.22.RELEASE baseline. Fixed upstream in: 2.5.15 / 2.6.15 / 2.7.12 / 3.0.7 — the CVE record names 2.5.14 and earlier as affected, which includes this baseline."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22733",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22733"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22733 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.12 / 4.0.4 (OSS); 2.7.32 / 3.3.18 / 3.4.15 are commercial-only (Tanzu), not on Maven Central; see component pedigree commit 01fbede2b27237616e215fe0df7c294ae47bdd73."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22733",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22733"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22733 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.12 / 4.0.4 (OSS); 2.7.32 / 3.3.18 / 3.4.15 are commercial-only (Tanzu), not on Maven Central; see component pedigree commit 01fbede2b27237616e215fe0df7c294ae47bdd73."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22733",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22733"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22733 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.12 / 4.0.4 (OSS); 2.7.32 / 3.3.18 / 3.4.15 are commercial-only (Tanzu), not on Maven Central; see component pedigree commit 01fbede2b27237616e215fe0df7c294ae47bdd73."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.003"
    } ]
  }, {
    "id" : "CVE-2026-22733",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22733"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22733 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.12 / 4.0.4 (OSS); 2.7.32 / 3.3.18 / 3.4.15 are commercial-only (Tanzu), not on Maven Central; see component pedigree commit 01fbede2b27237616e215fe0df7c294ae47bdd73."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.003"
    } ]
  }, {
    "id" : "CVE-2026-40972",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40972"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40972 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.14 / 4.0.6 (OSS); 2.7.33 / 3.3.19 / 3.4.16 are commercial-only (Tanzu), not on Maven Central; see component pedigree commit 4b0862cc00815a47b22339d7eac7ddc3b6645bd4."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.boot/spring-boot-devtools@2.7.18%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40982",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40982"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 3.1.10 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 3.1.x affected from 3.1.0 through 3.1.13, fixed only in 3.1.14 (Enterprise Support Only); see component pedigree commit 80de5a5b67a07898e13fd04cf7402f9e8dfecb06."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22739",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22739"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 3.1.10 baseline. Fixed upstream in: 4.3.2 / 5.0.2 — CNA records 3.1.x affected before 3.1.13; see component pedigree commit 1870f07befd5f62edcfdaea5ad82441d0fd49912."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41002",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41002"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 3.1.10 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 3.1.x affected from 3.1.0 through 3.1.13; see component pedigree commit cc71e5c3077732d44f0ef3afa439a0f73d6e70ce."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40982",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40982"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.1.0 through 4.1.10 affected; 4.1.10 is Enterprise Support Only; see component pedigree commit 80de5a5b67a07898e13fd04cf7402f9e8dfecb06."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22739",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22739"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.2 / 5.0.2 — CNA records 4.1.x affected before 4.1.9; see component pedigree commit 1870f07befd5f62edcfdaea5ad82441d0fd49912."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40981",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40981"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40981 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.1.0 through 4.1.10 affected; see component pedigree commit dec2b524fc2f2170dbee95d0412c0f63412ecf28."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41002",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41002"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.1.0 through 4.1.10 affected; see component pedigree commit cc71e5c3077732d44f0ef3afa439a0f73d6e70ce."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40982",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40982"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 (breaking Spring Boot 3.5 / dependency-train jump for the 4.2.x line); see component pedigree commit 7709cd0e016ce879e195620cf706bb30682073d4."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22739",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22739"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41002",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41002"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.2.0 through 4.2.7 affected."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40982",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40982"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 (breaking Spring Boot 3.5 / dependency-train jump for the 4.2.x line); see component pedigree commit 7709cd0e016ce879e195620cf706bb30682073d4."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22739",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22739"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41002",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41002"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.2.0 through 4.2.7 affected."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-40981",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40981"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40981 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.2.0 through 4.2.7 affected; see component pedigree commit dec2b524fc2f2170dbee95d0412c0f63412ecf28."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2022-22963",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22963"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22963 fixed by backporting the upstream fix onto the 3.1.6 baseline. Fixed upstream in: 3.1.7 and 3.2.3 (same org.springframework.cloud coordinate; 3.1.x line got the fix in 3.1.7, but consumers pinned to 3.1.6 have no in-place same-version fix)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-function-context@3.1.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22963",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22963"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22963 fixed by backporting the upstream fix onto the 3.1.6 baseline. Fixed upstream in: 3.1.7 and 3.2.3 (same org.springframework.cloud coordinate; 3.1.x line got the fix in 3.1.7, but consumers pinned to 3.1.6 have no in-place same-version fix)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-function-core@3.1.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22947",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22947"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22947 fixed by backporting the upstream fix onto the 2.2.10.RELEASE baseline. Fixed upstream in: 3.0.7 and 3.1.1 — never on the 2.2.x line, which was already EOL."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-41235",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-41235"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-41235 fixed by backporting the upstream fix onto the 2.2.10.RELEASE baseline. Fixed upstream in: 3.1.10 / 4.0.12 / 4.1.8 / 4.2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22947",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22947"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22947 fixed by backporting the upstream fix onto the 3.0.6 baseline. Fixed upstream in: 3.0.7 and 3.1.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@3.0.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22980",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22980"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22980 fixed by backporting the upstream fix onto the 3.1.15 baseline. Fixed upstream in: 3.3.5 and 3.4.1 (same coordinate; the 3.1.x line ended at 3.1.15 and never got the fix)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.1.15%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22980",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22980"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22980 fixed by backporting the upstream fix onto the 3.2.12 baseline. Fixed upstream in: 3.3.5 and 3.4.1 (same coordinate; the 3.2.x line ended at 3.2.12 and never got the fix)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.2.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it; see component pedigree commit 7ec5c994c147f0e168149498b1c9d4a249d69e87."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it; see component pedigree commit 297cbae2990e1413537c55845a7e0ea0ffd9f9bb."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it; see component pedigree commit 7678286fb3efa7bd7719ffe3055da9ed01e9f2f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it; see component pedigree commit 7ec5c994c147f0e168149498b1c9d4a249d69e87."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it; see component pedigree commit 297cbae2990e1413537c55845a7e0ea0ffd9f9bb."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it; see component pedigree commit 7678286fb3efa7bd7719ffe3055da9ed01e9f2f9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.0.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.0.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.0.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2022-22965",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22965"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22965 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.2.20.RELEASE / 5.3.18 — both later GENERATIONS, so the 5.1 line never received it and 5.1.20.RELEASE is terminal on Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 6.2.19 / 7.0.8 — the CNA's oldest enumerated range is 5.3.0-5.3.48 and does not name the 5.1 line; the defect is present here regardless, measured against the released jar (see notes)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2022-22965",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22965"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22965 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.2.20.RELEASE / 5.3.18 — both later GENERATIONS, so the 5.1 line never received it and 5.1.20.RELEASE is terminal on Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 6.2.19 / 7.0.8 — the CNA's oldest enumerated range is 5.3.0-5.3.48 and does not name the 5.1 line; the defect is present here regardless, measured against the released jar (see notes)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22243",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22243"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — OSS 5.2 ended at 5.2.25.RELEASE on 2023-07-13 and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22259",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22259"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — OSS 5.2 ended at 5.2.25.RELEASE and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22262",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22262"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — OSS 5.2 ended at 5.2.25.RELEASE and never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 6.2.19 / 7.0.8 — the CNA's oldest enumerated range is 5.3.0-5.3.48 and does not name the 5.2 line; the defect is present here regardless, measured against the released jar (see notes)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-aop@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-beans@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-context@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-core@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-expression@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-jdbc@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-messaging@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-orm@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-test@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-tx@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-webflux@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-38816",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38816"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support); see component pedigree commit d86bf8b2056429edf5494456cffcb2b243331c49."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-webmvc@5.3.39%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41848",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41848"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41848 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41845",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41845"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41848",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41848"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41848 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41007",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41007"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41007 fixed by backporting the upstream fix onto the 1.5.6 baseline. Fixed upstream in: 2.5.3 / 3.0.4 / 3.1 (no 1.5.x line fix — 1.5.x is EOL, terminal at 1.5.6); see component pedigree commit 668fd3282e1c7ffc817499b4b3d85d3aa21c0c2e."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41006",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41006"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41006 fixed by backporting the upstream fix onto the 1.5.6 baseline. Fixed upstream in: 2.5.3 / 3.0.4 (no 1.5.x line fix — 1.5.x is EOL, terminal at 1.5.6); see component pedigree commit 2c127edd741e43e6e6f06f4081af92d400209990."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2018-1263",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2018-1263"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2018-1263 fixed by backporting the upstream fix onto the 1.0.0.RELEASE baseline. Fixed upstream in: 1.0.2.RELEASE (a partial, '..'-gated fix shipped in 1.0.1.RELEASE; NVD marks the CVE fixed in 1.0.2); see component pedigree commit a5573eb232ff85199ff9bb28993df715d9a19a25."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.integration/spring-integration-zip@1.0.0.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-34040",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-34040"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-34040 fixed by backporting the upstream fix onto the 2.8.11 baseline. Fixed upstream in: 2.9.11 and 3.0.10 — the 2.8.x line was EOL and never patched, so the pinned 2.8.x coordinate has no same-line fix; see component pedigree commit eb779679812f61a8553ced3d0e4069dca65560ed."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.kafka/spring-kafka@2.8.11%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41720",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41720"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41720 fixed by backporting the upstream fix onto the 2.4.4 baseline. Fixed upstream in: 3.3.8 / 4.0.4 OSS (breaking line/major jump for 2.4.x and 3.2.x consumers); 2.4.5 / 3.2.17 are Enterprise-only, never on Central; see component pedigree commit e2748d44bdce4f6cb4663b9b8d8462e34808f09c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.ldap/spring-ldap-core@2.4.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22978",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22978"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22978 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.4.11 / 5.5.7 / 5.6.4 / 5.7.0 / 5.8.0 / 6.0.0 — the 4.2 line was EOL before the embargo and never received it; see component pedigree commit 1a9ec8a7565059ab73b2825375b23f14d0d4525c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-22112",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-22112"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-22112 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.2.9.RELEASE / 5.3.8.RELEASE / 5.4.4 / 5.5.0 — landed 2021-01-28, after 4.2.20.RELEASE was cut (2020-12-09) and after the 4.2 line was EOL; see component pedigree commit 7cab7b06c51ea885dd0d07ff26b135dd3afce1d1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22257",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22257"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22257 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.12 / 5.8.11 / 6.1.8 — the 4.2 line was a decade EOL; see component pedigree commit 5a7f12f1a9fdb4edaab6f61495f1d781a7273b61."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22978",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22978"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22978 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.4.11 / 5.5.7 / 5.6.4 / 5.7.0 / 5.8.0 / 6.0.0 — the 4.2 line was EOL before the embargo and never received it; see component pedigree commit 1a9ec8a7565059ab73b2825375b23f14d0d4525c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-22112",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-22112"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-22112 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.2.9.RELEASE / 5.3.8.RELEASE / 5.4.4 / 5.5.0 — landed 2021-01-28, after 4.2.20.RELEASE was cut (2020-12-09) and after the 4.2 line was EOL; see component pedigree commit 7cab7b06c51ea885dd0d07ff26b135dd3afce1d1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-22257",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22257"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22257 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.12 / 5.8.11 / 6.1.8 — the 4.2 line was a decade EOL; see component pedigree commit 5a7f12f1a9fdb4edaab6f61495f1d781a7273b61."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-22978",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22978"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22978 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.4.11 / 5.5.7 / 5.6.4 / 5.7.0 / 5.8.0 / 6.0.0 — the 4.2 line was EOL before the embargo and never received it; see component pedigree commit 1a9ec8a7565059ab73b2825375b23f14d0d4525c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2021-22112",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-22112"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-22112 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.2.9.RELEASE / 5.3.8.RELEASE / 5.4.4 / 5.5.0 — landed 2021-01-28, after 4.2.20.RELEASE was cut (2020-12-09) and after the 4.2 line was EOL; see component pedigree commit 7cab7b06c51ea885dd0d07ff26b135dd3afce1d1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22257",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22257"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22257 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.12 / 5.8.11 / 6.1.8 — the 4.2 line was a decade EOL; see component pedigree commit 5a7f12f1a9fdb4edaab6f61495f1d781a7273b61."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.22 / 5.8.24 / 6.3.15 / 6.4.15 / 6.5.9 / 7.0.4 — 4.2 is additionally worse off, because the shouldWriteHeadersEagerly opt-out that lets later versions avoid the lazy path only arrived in 5.7; see component pedigree commit 1dae9aa459436e0bb1a95701ed0d31e12be7788a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-38827",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38827"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38827 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.14 / 5.8.16 / 6.0.14 / 6.1.12 / 6.2.8 / 6.3.5 — the 4.2 line was a decade EOL; see component pedigree commit 0eaffb37e7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2022-22978",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-22978"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-22978 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.4.11 / 5.5.7 / 5.6.4 / 5.7.0 / 5.8.0 / 6.0.0 — the 4.2 line was EOL before the embargo and never received it; see component pedigree commit 1a9ec8a7565059ab73b2825375b23f14d0d4525c."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2021-22112",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-22112"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-22112 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.2.9.RELEASE / 5.3.8.RELEASE / 5.4.4 / 5.5.0 — landed 2021-01-28, after 4.2.20.RELEASE was cut (2020-12-09) and after the 4.2 line was EOL; see component pedigree commit 7cab7b06c51ea885dd0d07ff26b135dd3afce1d1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-22257",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-22257"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-22257 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.12 / 5.8.11 / 6.1.8 — the 4.2 line was a decade EOL; see component pedigree commit 5a7f12f1a9fdb4edaab6f61495f1d781a7273b61."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.22 / 5.8.24 / 6.3.15 / 6.4.15 / 6.5.9 / 7.0.4 — 4.2 is additionally worse off, because the shouldWriteHeadersEagerly opt-out that lets later versions avoid the lazy path only arrived in 5.7; see component pedigree commit 1dae9aa459436e0bb1a95701ed0d31e12be7788a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2024-38827",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-38827"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-38827 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.14 / 5.8.16 / 6.0.14 / 6.1.12 / 6.2.8 / 6.3.5 — the 4.2 line was a decade EOL; see component pedigree commit 0eaffb37e7."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2016-4977",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-4977"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-4977 fixed by backporting the upstream fix onto the 2.0.9.RELEASE baseline. Fixed upstream in: 2.0.10.RELEASE."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2018-1260",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2018-1260"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2018-1260 fixed by backporting the upstream fix onto the 2.0.9.RELEASE baseline. Fixed upstream in: 2.0.15.RELEASE."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2019-3778",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2019-3778"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2019-3778 fixed by backporting the upstream fix onto the 2.0.9.RELEASE baseline. Fixed upstream in: 2.0.17.RELEASE; see component pedigree commit 05166db04d61f24067db253cdebd7fea2bcf3d80."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31690",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31690"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31690 fixed by backporting the upstream fix onto the 5.5.8 baseline. Fixed upstream in: 5.6.9 / 5.7.5 — the 5.5 line was EOL before the fix and never received a release carrying it; see component pedigree commit e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.5.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31690",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31690"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31690 fixed by backporting the upstream fix onto the 5.5.8 baseline. Fixed upstream in: 5.6.9 / 5.7.5 — the 5.5 line was EOL before the fix and never received a release carrying it; see component pedigree commit e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.5.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31690",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31690"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31690 fixed by backporting the upstream fix onto the 5.5.8 baseline. Fixed upstream in: 5.6.9 / 5.7.5 — the 5.5 line was EOL before the fix and never received a release carrying it; see component pedigree commit e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-oauth2-client@5.5.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31690",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31690"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31690 fixed by backporting the upstream fix onto the 5.5.8 baseline. Fixed upstream in: 5.6.9 / 5.7.5 — the 5.5 line was EOL before the fix and never received a release carrying it; see component pedigree commit e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-oauth2-core@5.5.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31690",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31690"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31690 fixed by backporting the upstream fix onto the 5.5.8 baseline. Fixed upstream in: 5.6.9 / 5.7.5 — the 5.5 line was EOL before the fix and never received a release carrying it; see component pedigree commit e7fe778abc9afa96950cf0ab20a6a0ffbf9ab85f."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.5.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only; see component pedigree commit 46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only; see component pedigree commit 46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only; see component pedigree commit 46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central; see component pedigree commit 2e44a7c0c532fd2b096ce8ac676d690114b21afd."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only; see component pedigree commit 46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.0.16 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.0.16 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.0.16 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.0.16 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.1.14 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.1.14 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.1.14 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.1.14 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.2.10 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.2.10 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.2.10 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-22228",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-22228"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.2.10 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.3.10 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.3.10 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.3.10 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.3.10 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.4.13 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-config@6.4.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.4.13 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-core@6.4.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.4.13 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-crypto@6.4.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-22732",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-22732"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.4.13 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.security/spring-security-web@6.4.13%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40998",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40998"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40998 fixed by backporting the upstream fix onto the 4.0.17 baseline. Fixed upstream in: 4.1.4 / 5.0.2 OSS; 3.1.9 / 4.0.19 are Enterprise-support-only (never on Central); see component pedigree commit eb8d66c099."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.ws/spring-ws-core@4.0.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40998",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40998"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40998 fixed by backporting the upstream fix onto the 4.0.17 baseline. Fixed upstream in: 4.1.4 / 5.0.2 OSS; 3.1.9 / 4.0.19 are Enterprise-support-only (never on Central); see component pedigree commit eb8d66c099."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.springframework.ws/spring-xml@4.0.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.5.1 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-common@2.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.5.1 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-core@2.5.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-common@2.6.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-core@2.6.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.7.0 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-common@2.7.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.7.0 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-core@2.7.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.8.0 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-common@2.8.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.8.0 baseline. Fixed upstream in: 2.9.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-core@2.8.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.9.1 baseline. Fixed upstream in: 2.9.2; see component pedigree commit 5a8fe830b2a2308a2b24ac8115a391af477f64f5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-common@2.9.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-45047",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-45047"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.9.1 baseline. Fixed upstream in: 2.9.2; see component pedigree commit 5a8fe830b2a2308a2b24ac8115a391af477f64f5."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.sshd/sshd-core@2.9.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1181",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1181"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1181 fixed by a patch applied onto the 1.3.10 baseline; no upstream release carries this fix. Upstream status: none."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2016-1182",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2016-1182"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2016-1182 fixed by a patch applied onto the 1.3.10 baseline; no upstream release carries this fix. Upstream status: none."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2015-0899",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2015-0899"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2015-0899 fixed by a patch applied onto the 1.3.10 baseline; no upstream release carries this fix. Upstream status: none."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2024-53677",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2024-53677"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2024-53677 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.4.0 (via the replacement action-based upload mechanism; NO fix was ever released for the 2.5.x line, and 2.5.33 is terminal 2.5.x); see component pedigree commit d2d01dfe93add786a65b3fd5b13cacaa7be0d99b."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66675",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66675"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66675 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.8.0 / 7.1.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-64775",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-64775"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-64775 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.8.0 / 7.1.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-68493",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-68493"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-68493 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.1.1 (the fix commit is in the STRUTS_6_1_0 tag, but 6.1.0 was never released to Central — 6.1.1 is the first RELEASE carrying it); see component pedigree commit 6658c6360."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-50164",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-50164"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-50164 fixed by backporting the upstream fix onto the 2.3.37 baseline. Fixed upstream in: 2.5.33 and 6.3.0.2 (no fix ever released in the 2.3.x line — 2.3.37 is terminal 2.3.x and is affected); see component pedigree commit 162e29fee9136f4bfd9b2376da2cbf590f9ea163."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts/struts2-core@2.3.37%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-17531",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-17531"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-17531 fixed by a patch applied onto the 4.1.6 baseline; no upstream release carries this fix. Upstream status: none (Tapestry 4 EOL 2008; Apache declined to patch the 4.x line and the advisory says upgrade to Tapestry 5.x, a full rewrite); see component pedigree commit fdb3d7c970352a6692c769942dd9b2c81364b709."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-17531",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-17531"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-17531 fixed by a patch applied onto the 4.1.6 baseline; no upstream release carries this fix. Upstream status: none (Tapestry 4 EOL 2008; Apache declined to patch the 4.x line and the advisory says upgrade to Tapestry 5.x, a full rewrite); see component pedigree commit fdb3d7c970352a6692c769942dd9b2c81364b709."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2021-27850",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-27850"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-27850 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.6.3 / 5.7.1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-30638",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-30638"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-30638 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.6.4 / 5.7.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-13953",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-13953"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-13953 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.6.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-31781",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-31781"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-31781 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.8.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43869",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43869"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43869 fixed by backporting the upstream fix onto the 0.13.0 baseline. Fixed upstream in: 0.23.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.thrift/libthrift@0.13.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40478",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40478"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit 76680a7200548fd26b9234e58a59d6b2ca46ebfa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41901",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41901"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE; see component pedigree commit 8af2373885970a7946b738d6f66d1f2a7e4fa799."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40478",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40478"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit 76680a7200548fd26b9234e58a59d6b2ca46ebfa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41901",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41901"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE; see component pedigree commit 8af2373885970a7946b738d6f66d1f2a7e4fa799."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40478",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40478"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit 76680a7200548fd26b9234e58a59d6b2ca46ebfa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41901",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41901"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE; see component pedigree commit 8af2373885970a7946b738d6f66d1f2a7e4fa799."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-40478",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40478"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit 76680a7200548fd26b9234e58a59d6b2ca46ebfa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41901",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41901"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE; see component pedigree commit 8af2373885970a7946b738d6f66d1f2a7e4fa799."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-40477",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40477"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40477 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit c115713f6d73a4c0e2d83b1fb9e385db4199fb2a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-40478",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40478"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit 76680a7200548fd26b9234e58a59d6b2ca46ebfa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41901",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41901"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE; see component pedigree commit 8af2373885970a7946b738d6f66d1f2a7e4fa799."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-40477",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40477"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40477 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit c115713f6d73a4c0e2d83b1fb9e385db4199fb2a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-40478",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40478"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit 76680a7200548fd26b9234e58a59d6b2ca46ebfa."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41901",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41901"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE; see component pedigree commit 8af2373885970a7946b738d6f66d1f2a7e4fa799."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-40477",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-40477"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-40477 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE; see component pedigree commit c115713f6d73a4c0e2d83b1fb9e385db4199fb2a."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 1.28.5 baseline. Fixed upstream in: 3.2.2 (tika-core; the fix hardens getXMLInputFactory — no 1.x/2.9.x release carried it)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-54988",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-54988"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-54988 fixed by backporting the upstream fix onto the 1.28.5 baseline. Fixed upstream in: 3.2.2 (same commits as CVE-2025-66516 — bfee6d5569 + fd2016ffe4 on getXMLInputFactory; nothing in the PDF/XFA module changed)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.1.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.1.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.2.1 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.2.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.3.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.3.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.4.1 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.4.1%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.5.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.5.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.6.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.7.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.7.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.8.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.8.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66516",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66516"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.9.4 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-54988",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-54988"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-54988 fixed by backporting the upstream fix onto the 2.9.4 baseline. Fixed upstream in: 3.2.2 (same commits as CVE-2025-66516; nothing in the PDF/XFA module changed)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-49735",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-49735"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-49735 fixed by a patch applied onto the 3.0.8 baseline; no upstream release carries this fix. Upstream status: none (project retired to the Apache Attic; the advisory is marked UNSUPPORTED WHEN ASSIGNED)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tiles/tiles-api@3.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2023-49735",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2023-49735"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2023-49735 fixed by a patch applied onto the 3.0.8 baseline; no upstream release carries this fix. Upstream status: none (project retired to the Apache Attic; the advisory is marked UNSUPPORTED WHEN ASSIGNED)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tiles/tiles-core@3.0.8%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line was EOL and received no fixed release; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line was EOL and received no fixed release; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-41293",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41293"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "8.0 has no HTTP/2 implementation; the shipped jar contains no org/apache/coyote/http2 entry."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66614",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66614"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "The CNA states nothing below 8.5.0 is affected; 8.0 has no SSLHostConfig, so there is no second host config to redirect to."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-1938",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-1938"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-1938 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 7.0.100 / 8.5.51 / 9.0.31, of which this ships the code half — the block on the vector that returns arbitrary files and executes them as JSP. Upstream's other half hardens the DEFAULT AJP connector configuration, which no jar can ship and which this baseline can already do by hand; see notes and known_open_cves is deliberately not used for it. The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit b99fba5bd796d876ea536e83299603443842feba."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-41293",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-41293"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "8.0 has no HTTP/2 implementation; the shipped jar contains no org/apache/coyote/http2 entry."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-66614",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66614"
    },
    "analysis" : {
      "state" : "not_affected",
      "justification" : "code_not_present",
      "detail" : "The CNA states nothing below 8.5.0 is affected; 8.0 has no SSLHostConfig, so there is no second host config to redirect to."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2025-66614",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66614"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66614 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.113 (also 10.1.50, 11.0.15). The 8.5.x line was EOL and received NO fixed release; see component pedigree commit 152c14885d45f5e0a8b59bd9f93c289cfe20ce30."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2026-32990",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-32990"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-32990 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.116 (case-insensitive comparison; also main/11.0.x/10.1.x); see component pedigree commit 95f7778248cac46d03e6af04de9c72a598be3a53."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-66614",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-66614"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-66614 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.113 (also 10.1.50, 11.0.15). The 8.5.x line was EOL and received NO fixed release; see component pedigree commit 152c14885d45f5e0a8b59bd9f93c289cfe20ce30."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-32990",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-32990"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-32990 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.116 (case-insensitive comparison; also main/11.0.x/10.1.x); see component pedigree commit 95f7778248cac46d03e6af04de9c72a598be3a53."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-43512",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43512"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line EOL'd at 8.5.100 and received no fixed release; the CNA lists 8.5.0 through 8.5.100 as affected; see component pedigree commit 6565a6cb6499e56fe2f34457cec99f9d1c4f39e9."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-43515",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43515"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line EOL'd at 8.5.100 and received no fixed release; the CNA lists 8.5.0 through 8.5.100 as affected; see component pedigree commit db919ff9912b4d61d1b702a1342b8bde39270031."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
    } ]
  }, {
    "id" : "CVE-2026-29146",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-29146"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2026-29146 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.116 (also 10.1.53, 11.0.19). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.100 through 7.0.109 as affected; see component pedigree commit 0112ed22abfccc3d54e44d91eb08804d0886acd1."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.tomcat/tomcat-tribes@7.0.109%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-3629",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-3629"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-3629 fixed by backporting the upstream fix onto the 2.2.3.Final baseline. Fixed upstream in: 2.2.11.Final (also 2.0.40.Final on the 2.0.x line)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/io.undertow/undertow-core@2.2.3.Final%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-13936",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-13936"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-13936 fixed by a patch applied onto the 1.7 baseline; no upstream release carries this fix. Upstream status: none (fix shipped only under the new velocity-engine-core coordinate, 2.3)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.velocity/velocity@1.7%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2020-13936",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2020-13936"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2020-13936 fixed by backporting the upstream fix onto the 2.2 baseline. Fixed upstream in: 2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.velocity/velocity-engine-core@2.2%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2012-0881",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2012-0881"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2012-0881 fixed by backporting the upstream fix onto the 2.11.0 baseline. Fixed upstream in: 2.12.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2013-4002",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2013-4002"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2013-4002 fixed by backporting the upstream fix onto the 2.11.0 baseline. Fixed upstream in: 2.12.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2022-23437",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2022-23437"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2022-23437 fixed by backporting the upstream fix onto the 2.11.0 baseline. Fixed upstream in: 2.12.2."
    },
    "affects" : [ {
      "ref" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-23926",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-23926"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-23926 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 3.0.0."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.xmlbeans/xmlbeans@2.6.0%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-40690",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-40690"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-40690 fixed by backporting the upstream fix onto the 2.1.4 baseline. Fixed upstream in: 2.1.7 and 2.2.3."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.santuario/xmlsec@2.1.4%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2021-39144",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2021-39144"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2021-39144 fixed by backporting the upstream fix onto the 1.4.17 baseline. Fixed upstream in: 1.4.18."
    },
    "affects" : [ {
      "ref" : "pkg:maven/com.thoughtworks.xstream/xstream@1.4.17%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-68493",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-68493"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-68493 fixed by backporting the upstream fix onto the 2.3.37 baseline. Fixed upstream in: 6.1.1 (nothing on this coordinate — upstream's remedy landed after xwork-core had been folded into struts2-core, so the standalone org.apache.struts.xwork:xwork-core artifact never received it)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.001"
    } ]
  }, {
    "id" : "CVE-2025-68493",
    "source" : {
      "name" : "NVD",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-68493"
    },
    "analysis" : {
      "state" : "resolved_with_pedigree",
      "detail" : "CVE-2025-68493 fixed by backporting the upstream fix onto the 2.3.37 baseline. Fixed upstream in: 6.1.1 (nothing on this coordinate — upstream's remedy landed after xwork-core had been folded into struts2-core, so the standalone org.apache.struts.xwork:xwork-core artifact never received it)."
    },
    "affects" : [ {
      "ref" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.002"
    } ]
  } ]
}