{
  "@context" : "https://openvex.dev/ns/v0.2.0",
  "@id" : "https://vex.backpatch.moderne.io/openvex/all.json",
  "author" : "Moderne Backpatch Alliance <support@moderne.io>",
  "role" : "Document Creator",
  "timestamp" : "2026-09-01T07:42:04Z",
  "version" : 1,
  "statements" : [ {
    "vulnerability" : {
      "name" : "CVE-2023-46604",
      "aliases" : [ "BIT-activemq-2023-46604", "GHSA-crg9-44h2-xw35" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.activemq/activemq-client@5.14.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.activemq/activemq-client@5.14.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.apache.activemq/activemq-broker@5.14.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.activemq/activemq-broker@5.14.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.apache.activemq/activemq-openwire-legacy@5.14.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.activemq/activemq-openwire-legacy@5.14.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-46604 fixed by backporting the upstream fix onto the 5.14.5 baseline. Fixed upstream in: 5.15.16 / 5.16.7 / 5.17.6 / 5.18.3 / 6.0.0 (all terminal releases of already-EOL branches; nothing at 5.14.x or earlier)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-27446",
      "aliases" : [ "GHSA-fw88-pf9m-p947" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.activemq/artemis-server@2.44.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.activemq/artemis-server@2.44.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c731fb739cba9879859083820e7781b5a18bd116909fb6f03cd31fb2c40806ff"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-27446 fixed by backporting the upstream fix onto the 2.44.0 baseline. Fixed upstream in: 2.52.0, published as org.apache.artemis:artemis-server — org.apache.activemq:artemis-server:2.52.0 is a relocation POM with no jar"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47561",
      "aliases" : [ "GHSA-r7pg-v2c8-mfg3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.avro/avro@1.11.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.avro/avro@1.11.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8ba799f4e9fd0da9d9c5acc6f510c7d72cf2933902238da8fdd444e6b0bd67fb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47561 fixed by backporting the upstream fix onto the 1.11.3 baseline. Fixed upstream in: 1.11.4 / 1.12.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000338",
      "aliases" : [ "GHSA-4vhj-98r6-424h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000338 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000341",
      "aliases" : [ "GHSA-r9ch-m4fh-fc7q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000341 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000342",
      "aliases" : [ "GHSA-qcj7-g2j5-g7r3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000342 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000343",
      "aliases" : [ "GHSA-rrvx-pwf8-p59p" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000343 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000344",
      "aliases" : [ "GHSA-2j2x-hx4g-2gf4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000344 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000352",
      "aliases" : [ "GHSA-w285-wf9q-5w69" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000352 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-26939",
      "aliases" : [ "GHSA-72m5-fvvv-55m6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-26939 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.61"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000338",
      "aliases" : [ "GHSA-4vhj-98r6-424h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000338 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000341",
      "aliases" : [ "GHSA-r9ch-m4fh-fc7q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000341 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000342",
      "aliases" : [ "GHSA-qcj7-g2j5-g7r3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000342 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.56"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-26939",
      "aliases" : [ "GHSA-72m5-fvvv-55m6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-26939 fixed by backporting the upstream fix onto the 1.47 baseline. Fixed upstream in: 1.61"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000343",
      "aliases" : [ "GHSA-rrvx-pwf8-p59p" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "1.47 rejects DSA strength > 1024 at the API boundary, so the >1024-with-160-bit-q pairing the CVE describes cannot be reached; the 1.47 and 1.56 defaults are identical (p=1024, q=160)."
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000344",
      "aliases" : [ "GHSA-2j2x-hx4g-2gf4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "1.47 registers only KDF2+HMAC IES via JCEIESCipher; the DHIESwithAES variant the 1.56 fix removes does not exist here."
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000352",
      "aliases" : [ "GHSA-w285-wf9q-5w69" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15on@1.47%2Bbackpatch.002"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "1.47 registers only KDF2+HMAC ECIES via JCEIESCipher; the ECIESwithAES variant the 1.56 fix removes does not exist here."
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000338",
      "aliases" : [ "GHSA-4vhj-98r6-424h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "efb97aa5fae48e0f4ca2b3f66154f1973d1d63ce10c19adef838be6738fec3b1"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000338 fixed by backporting the upstream fix onto the 1.46 baseline. Fixed upstream in: 1.56 (on the -jdk15on coordinate only)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000342",
      "aliases" : [ "GHSA-qcj7-g2j5-g7r3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.bouncycastle/bcprov-jdk15@1.46%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "efb97aa5fae48e0f4ca2b3f66154f1973d1d63ce10c19adef838be6738fec3b1"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000342 fixed by backporting the upstream fix onto the 1.46 baseline. Fixed upstream in: 1.56 (on the -jdk15on coordinate only)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2018-20433",
      "aliases" : [ "GHSA-q485-j897-qc27" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.mchange/c3p0@0.9.5.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.mchange/c3p0@0.9.5.2%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2018-20433 fixed by backporting the upstream fix onto the 0.9.5.2 baseline. Fixed upstream in: 0.9.5.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-39135",
      "aliases" : [ "GHSA-fj2m-w3wv-x9pr" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.calcite/calcite-core@1.29.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.calcite/calcite-core@1.29.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ac01cfa3c03efe086a07231602df225cf220f7cb461a349b6b34a8d57b4e6bb6"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-39135 fixed by backporting the upstream fix onto the 1.29.0 baseline. Fixed upstream in: 1.32.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-39135",
      "aliases" : [ "GHSA-fj2m-w3wv-x9pr" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.calcite/calcite-core@1.30.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.calcite/calcite-core@1.30.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ad6b346076f5e04229106d216682d8e5118c0e2577a06a30344c928e8a9c2406"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-39135 fixed by backporting the upstream fix onto the 1.30.0 baseline. Fixed upstream in: 1.32.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-39135",
      "aliases" : [ "GHSA-fj2m-w3wv-x9pr" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.calcite/calcite-core@1.31.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.calcite/calcite-core@1.31.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "35af7482674a968e0c5dfbb0a826722c342fe181cecf654a64005614271172dc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-39135 fixed by backporting the upstream fix onto the 1.31.0 baseline. Fixed upstream in: 1.32.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-11971",
      "aliases" : [ "GHSA-hfg5-xpvw-c9x4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-11971",
      "aliases" : [ "GHSA-hfg5-xpvw-c9x4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-11971",
      "aliases" : [ "GHSA-hfg5-xpvw-c9x4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.003",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.003"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-11971",
      "aliases" : [ "GHSA-hfg5-xpvw-c9x4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.camel/camel-core@2.25.4%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-11971 fixed by backporting the upstream fix onto the 2.25.4 baseline. Fixed upstream in: 3.2.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-48734",
      "aliases" : [ "GHSA-wxr5-93ph-8wr9" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c318dcfb461e10d5cb8b478f9e26cb3138c94b9a5e94c312312a79187bbd933a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-48734 fixed by backporting the upstream fix onto the 1.9.4 baseline. Fixed upstream in: 1.11.0 (commit 28ad955a); also 2.0.0-M2 on the org.apache.commons:commons-beanutils2 coordinate"
  }, {
    "vulnerability" : {
      "name" : "CVE-2014-0114",
      "aliases" : [ "GHSA-p66x-2cv9-qq3v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "aef18ccc3f0b2f291ba102c691785c86b1c9ad233382739fe0eb2e0553677d25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2014-0114 fixed by backporting the upstream fix onto the 1.9.2 baseline. Fixed upstream in: 1.9.4 (BEANUTILS-520, commit 62e82ad9)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-10086",
      "aliases" : [ "GHSA-6phf-73q6-gh87" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-beanutils/commons-beanutils@1.9.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "aef18ccc3f0b2f291ba102c691785c86b1c9ad233382739fe0eb2e0553677d25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-10086 fixed by backporting the upstream fix onto the 1.9.2 baseline. Fixed upstream in: 1.9.4 (same commit 62e82ad9 — the SUPPRESS_CLASS-by-default change)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-7501",
      "aliases" : [ "GHSA-fjq5-5j5f-mvxh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "25a66f3767667b8c18cc46db0213d3c6fe60afa75001561f1d139a1a56595fcd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2015-7501 fixed by backporting the upstream fix onto the 3.2.1 baseline. Fixed upstream in: 3.2.2 (COLLECTIONS-580)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-6420",
      "aliases" : [ "GHSA-6hgm-866r-3cjv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-collections/commons-collections@3.2.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "25a66f3767667b8c18cc46db0213d3c6fe60afa75001561f1d139a1a56595fcd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2015-6420 fixed by backporting the upstream fix onto the 3.2.1 baseline. Fixed upstream in: 3.2.2 (COLLECTIONS-580)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-7501",
      "aliases" : [ "GHSA-fjq5-5j5f-mvxh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3445b9c4342d8e1a6746957390372ab5cbc6eed7d838d6c733a70fcb3c604af5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2015-7501 fixed by backporting the upstream fix onto the 4.0 baseline. Fixed upstream in: 4.1 (COLLECTIONS-580) — NOT ported; see fix_description"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-6420",
      "aliases" : [ "GHSA-6hgm-866r-3cjv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-collections4@4.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3445b9c4342d8e1a6746957390372ab5cbc6eed7d838d6c733a70fcb3c604af5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2015-6420 fixed by backporting the upstream fix onto the 4.0 baseline. Fixed upstream in: 4.1 (COLLECTIONS-580) — NOT ported; see fix_description"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-35515",
      "aliases" : [ "GHSA-7hfm-57qf-j43q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "71e8a3e592d853c7c7bdb64536e25b51dca38f6a131c2210767abf966c84e1be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-35515 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-35516",
      "aliases" : [ "GHSA-crv7-7245-f45f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "71e8a3e592d853c7c7bdb64536e25b51dca38f6a131c2210767abf966c84e1be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-35516 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-35517",
      "aliases" : [ "GHSA-xqfj-vm6h-2x34" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "71e8a3e592d853c7c7bdb64536e25b51dca38f6a131c2210767abf966c84e1be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-35517 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-36090",
      "aliases" : [ "GHSA-mc84-pj99-q6hh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-compress@1.20%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "71e8a3e592d853c7c7bdb64536e25b51dca38f6a131c2210767abf966c84e1be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-36090 fixed by backporting the upstream fix onto the 1.20 baseline. Fixed upstream in: 1.21"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-1953",
      "aliases" : [ "GHSA-7qx4-pp76-vrqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "73326034b78811ab5938916b3c01961f1d8a6d16f6cc3d252b1bf78fe06bebea"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-1953 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-33980",
      "aliases" : [ "GHSA-xj57-8qj4-c4m6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "73326034b78811ab5938916b3c01961f1d8a6d16f6cc3d252b1bf78fe06bebea"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-33980 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.8.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-33980",
      "aliases" : [ "GHSA-xj57-8qj4-c4m6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-configuration2@2.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9f4bd7bf785e4dbcf5ee33b059468a5cd4576a733c18643371c45be0833b63ef"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-33980 fixed by backporting the upstream fix onto the 2.7 baseline. Fixed upstream in: 2.8.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-1953",
      "aliases" : [ "GHSA-7qx4-pp76-vrqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8ff1c4eccef6b54c4e484ccf5ff9bc27f4c339ed1f1c28c284568398758d84de"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-1953 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-33980",
      "aliases" : [ "GHSA-xj57-8qj4-c4m6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-configuration2@2.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8ff1c4eccef6b54c4e484ccf5ff9bc27f4c339ed1f1c28c284568398758d84de"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-33980 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.8.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1000031",
      "aliases" : [ "GHSA-7x9j-7223-rg5m" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45f894e8ad8d4073d36d6cbcadaccd43bc62646cddedcaab845503ae1dd66023"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1000031 fixed by backporting the upstream fix onto the 1.3.1 baseline. Fixed upstream in: 1.3.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-3092",
      "aliases" : [ "GHSA-fvm3-cfvj-gxqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45f894e8ad8d4073d36d6cbcadaccd43bc62646cddedcaab845503ae1dd66023"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-3092 fixed by backporting the upstream fix onto the 1.3.1 baseline. Fixed upstream in: 1.3.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-24998",
      "aliases" : [ "GHSA-hfrx-6qgj-fp6c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-fileupload/commons-fileupload@1.3.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45f894e8ad8d4073d36d6cbcadaccd43bc62646cddedcaab845503ae1dd66023"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-24998 fixed by backporting the upstream fix onto the 1.3.1 baseline. Fixed upstream in: 1.5"
  }, {
    "vulnerability" : {
      "name" : "CVE-2012-5783",
      "aliases" : [ "GHSA-3832-9276-x7gf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-httpclient/commons-httpclient@3.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-httpclient/commons-httpclient@3.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4907385ea2fc94558a975b1a460423d9356c45a08e1262863f1ea82bfa237117"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2012-5783 fixed by a patch applied onto the 3.1 baseline; no upstream release carries this fix. Upstream status: none released (svn r1422573)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "adf90d86851cd5d25c362ef0d0c313fb929cf785f6a19301762f531995eb50a8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.0.1 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.0.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "adf90d86851cd5d25c362ef0d0c313fb929cf785f6a19301762f531995eb50a8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.0.1 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b87caae4d0a82c42d51467c54d824f43bde7350cd690e9ed9a9fbb13aab7bfc9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.1 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b87caae4d0a82c42d51467c54d824f43bde7350cd690e9ed9a9fbb13aab7bfc9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.1 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1743bad71fc0f8459ff1d7fbc47bc430b0db17359b86539c659170e0d176a730"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.2 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1743bad71fc0f8459ff1d7fbc47bc430b0db17359b86539c659170e0d176a730"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.2 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "92a82c53d0b34a391b9fe9ce2a13165592be0472fdcce15c2e7b55e8771d11e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.3 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "92a82c53d0b34a391b9fe9ce2a13165592be0472fdcce15c2e7b55e8771d11e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.3 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cb038938ca50a852ab61810743ab595c760a77271dcf1db248251a0dd773b067"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.4 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cb038938ca50a852ab61810743ab595c760a77271dcf1db248251a0dd773b067"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.4 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b9e75b780f1b09a439ed496828cccdccfbb4f89b98d8cc898b4891b642657d33"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b9e75b780f1b09a439ed496828cccdccfbb4f89b98d8cc898b4891b642657d33"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.5 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "fde9ae5437a654d54cc12c36bc6cb364bb9488cbfe44560f0c28f72ace06d07f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "fde9ae5437a654d54cc12c36bc6cb364bb9488cbfe44560f0c28f72ace06d07f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-29425",
      "aliases" : [ "GHSA-gwrp-pvrq-jmwv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c68a5fc84231e0374e9e45bcd20c494680c27da61b7bce907245de17289be810"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-29425 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-47554",
      "aliases" : [ "GHSA-78wr-2p64-hpwj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c68a5fc84231e0374e9e45bcd20c494680c27da61b7bce907245de17289be810"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-47554 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.14.0"
  }, {
    "vulnerability" : {
      "name" : "XRAY-125253"
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/commons-io/commons-io@2.6%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c68a5fc84231e0374e9e45bcd20c494680c27da61b7bce907245de17289be810"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "XRAY-125253 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: 2.8.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-48924",
      "aliases" : [ "GHSA-j288-q9x7-2f5v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/commons-lang/commons-lang@2.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/commons-lang/commons-lang@2.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e2bbb0e81b016063470a39362a691fe658092270555b38de984e03d65afae311"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-48924 fixed by backporting the upstream fix onto the 2.6 baseline. Fixed upstream in: org.apache.commons:commons-lang3 3.18.0 (a DIFFERENT coordinate). NOT fixed in the legacy commons-lang:commons-lang 2.x line, which is EOL at 2.6 (none)."
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-42889",
      "aliases" : [ "GHSA-599f-7c49-w659" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.commons/commons-text@1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.commons/commons-text@1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "988463b04593b2ae8d4690ca4206eeb0478f53892401460014a7300be000c539"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-42889 fixed by backporting the upstream fix onto the 1.9 baseline. Fixed upstream in: 1.10.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-46364",
      "aliases" : [ "GHSA-x3x3-qwjq-8gj4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b278f3384a529395d67ea9732afdc0c6c656af92131db59399c42f3fbda828b7"
      }
    }, {
      "@id" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e3644a5faae2168dd5f4f86fe3966ec71065cf3c79acf2a071b92ab1d7268766"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-46364 fixed by backporting the upstream fix onto the 3.3.13 baseline. Fixed upstream in: 3.4.10 / 3.5.5 — no 3.3.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-46363",
      "aliases" : [ "GHSA-3w37-5p3p-jv92" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.cxf/cxf-core@3.3.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b278f3384a529395d67ea9732afdc0c6c656af92131db59399c42f3fbda828b7"
      }
    }, {
      "@id" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.cxf/cxf-rt-transports-http@3.3.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e3644a5faae2168dd5f4f86fe3966ec71065cf3c79acf2a071b92ab1d7268766"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-46363 fixed by backporting the upstream fix onto the 3.3.13 baseline. Fixed upstream in: 3.4.10 / 3.5.5 — no 3.3.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-48913",
      "aliases" : [ "GHSA-g4px-6qhm-hqjm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.cxf/cxf-rt-transports-jms@3.5.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.cxf/cxf-rt-transports-jms@3.5.11%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.apache.cxf/cxf-core@3.5.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.cxf/cxf-core@3.5.11%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-48913 fixed by backporting the upstream fix onto the 3.5.11 baseline. Fixed upstream in: 3.6.8 / 4.0.9 / 4.1.3 (different minor/major lines; no 3.5.12 exists)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-10683",
      "aliases" : [ "GHSA-hwj3-m3p6-hj38" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/dom4j/dom4j@1.6.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/dom4j/dom4j@1.6.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-10683 fixed by backporting the upstream fix onto the 1.6.1 baseline. Fixed upstream in: org.dom4j:dom4j 2.0.3 / 2.1.3 (different groupId — NVD/GHSA treat them as distinct package identities)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-23457",
      "aliases" : [ "GHSA-8m5h-hrqm-pxm2" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.owasp.esapi/esapi@2.2.3.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.owasp.esapi/esapi@2.2.3.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "53eb34020410b0050d0ed0ce5e11969fd5235644008334f658e684cad75b1856"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-23457 fixed by backporting the upstream fix onto the 2.2.3.1 baseline. Fixed upstream in: 2.3.0.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25845",
      "aliases" : [ "GHSA-pv7h-hx5h-mgfj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5ec4805437cb95737bf6bbf73fbaaebb91334f9695aa07464211eb0dd528a75a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25845 fixed by backporting the upstream fix onto the 1.2.68 baseline. Fixed upstream in: 1.2.83"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25845",
      "aliases" : [ "GHSA-pv7h-hx5h-mgfj", "SNYK-JAVA-COMALIBABA-2859222" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/com.alibaba/fastjson@1.2.68%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "1ee09de4e801eb064a971c5f30fa74e5928980f66b5ac1110c353cdf6f1e16a3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25845 fixed by backporting the upstream fix onto the 1.2.68 baseline. Fixed upstream in: 1.2.83"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-40094",
      "aliases" : [ "GHSA-h9mq-f6q5-6c8m" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.graphql-java/graphql-java@18.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.graphql-java/graphql-java@18.7%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-40094 fixed by backporting the upstream fix onto the 18.7 baseline. Fixed upstream in: 19.11, 20.9, 21.5, 22.0+ (same com.graphql-java:graphql-java coordinate, but only in newer lines; no 18.x fix — 18.x is EOL)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25647",
      "aliases" : [ "GHSA-4jrv-ppp4-jm57" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.code.gson/gson@2.8.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.code.gson/gson@2.8.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2575baa2fd678a378998e9c3f238d68bdffe327303c00192401eff3ee570be17"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25647 fixed by backporting the upstream fix onto the 2.8.8 baseline. Fixed upstream in: 2.8.9"
  }, {
    "vulnerability" : {
      "name" : "CVE-2018-10237",
      "aliases" : [ "GHSA-mvr2-9pj6-7w5j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4bf902166aadcdb40f8cd44b3d022b288af2d89c4adae3a884f560d604bb6523"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2018-10237 fixed by backporting the upstream fix onto the 20.0 baseline. Fixed upstream in: 24.1.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-2976",
      "aliases" : [ "GHSA-7g45-4rm6-3mm3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4bf902166aadcdb40f8cd44b3d022b288af2d89c4adae3a884f560d604bb6523"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-2976 fixed by backporting the upstream fix onto the 20.0 baseline. Fixed upstream in: 32.0.0-jre"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-8908",
      "aliases" : [ "GHSA-5mg8-w23w-74h3", "SNYK-JAVA-COMGOOGLEGUAVA-1015415" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.guava/guava@20.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4bf902166aadcdb40f8cd44b3d022b288af2d89c4adae3a884f560d604bb6523"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-8908 fixed by backporting the upstream fix onto the 20.0 baseline. Fixed upstream in: 32.0.0-jre"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-2976",
      "aliases" : [ "GHSA-7g45-4rm6-3mm3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c67a840999b3e5d99dc3f5fd428e8041aee3ed9f3f79274203ecada96aaef456"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-2976 fixed by backporting the upstream fix onto the 31.1-jre baseline. Fixed upstream in: 32.0.0-jre"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-8908",
      "aliases" : [ "GHSA-5mg8-w23w-74h3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.guava/guava@31.1-jre%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c67a840999b3e5d99dc3f5fd428e8041aee3ed9f3f79274203ecada96aaef456"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-8908 fixed by backporting the upstream fix onto the 31.1-jre baseline. Fixed upstream in: 32.0.0-jre"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-42392",
      "aliases" : [ "GHSA-h376-j262-vhq6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-42392 fixed by backporting the upstream fix onto the 1.4.200 baseline. Fixed upstream in: 2.0.206"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-42392",
      "aliases" : [ "GHSA-h376-j262-vhq6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-42392 fixed by backporting the upstream fix onto the 1.4.200 baseline. Fixed upstream in: 2.0.206"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-23463",
      "aliases" : [ "GHSA-7rpj-hg47-cx62", "SNYK-JAVA-COMH2DATABASE-1769238" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/com.h2database/h2@1.4.200%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-23463 fixed by backporting the upstream fix onto the 1.4.200 baseline. Fixed upstream in: 2.0.202"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25168",
      "aliases" : [ "GHSA-8wm5-8h9c-47pc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bdd9b21f11f0d71f15f8e633ccc76c56bb520cef44d56e94aa65903fc39316ba"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25168",
      "aliases" : [ "GHSA-8wm5-8h9c-47pc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "4ee74fda4d9da19746c2e78c5bb3fdab55825f8ff17faf267166f44097c182e7"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25168",
      "aliases" : [ "GHSA-8wm5-8h9c-47pc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.003",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.003"
      },
      "hashes" : {
        "sha-256" : "e89de6e44a5699fb8a2c1a98d638734f3f183906b0df540c1ce2d31b0fbe32d6"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25168",
      "aliases" : [ "GHSA-8wm5-8h9c-47pc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.7.7%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "1842bf7b517b4bc52c6c4c9f0bb8a11431e39950381720dc510b54f52556e1b8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.7.7 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25168",
      "aliases" : [ "GHSA-8wm5-8h9c-47pc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "27dbd447221707562f852d090b16eea17d005d7f562c8de9f09e314aae296271"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.8.5 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-25168",
      "aliases" : [ "GHSA-8wm5-8h9c-47pc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.hadoop/hadoop-common@2.8.5%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "e1450d47f3ed794e488da9d25ebaaf9a42d6ed84cb089e2cb9e8b875e4bc4f42"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-25168 fixed by backporting the upstream fix onto the 2.8.5 baseline. Fixed upstream in: 2.10.2 / 3.2.4 / 3.3.3 (HADOOP-18136)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-10750",
      "aliases" : [ "GHSA-jv65-pf7v-f7p8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b85653ca4eef794f5b534fa8ab441dd16bf0fad3780e59958b5c92c1e50d05a4"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-10750 fixed by backporting the upstream fix onto the 3.10.6 baseline. Fixed upstream in: 3.11 (commit 5a47697519 — JavaSerializationFilterConfig class-filter feature)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-10750",
      "aliases" : [ "GHSA-jv65-pf7v-f7p8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/com.hazelcast/hazelcast@3.10.6%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "f2fe95e49993b774cbd0264904a31bfffedfd91bcd42ad15af776975b02613f5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-10750 fixed by backporting the upstream fix onto the 3.10.6 baseline. Fixed upstream in: 3.11 (commit 5a47697519 — JavaSerializationFilterConfig class-filter feature)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-0603",
      "aliases" : [ "GHSA-2p5w-cvg5-gc5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.hibernate/hibernate-core@5.4.33.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.hibernate/hibernate-core@5.4.33.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "36b2e297a66a4168494257765b6e0f64955c8a5d09b6ee17510312548f06bd25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-0603 fixed by backporting the upstream fix onto the 5.4.33.Final baseline. Fixed upstream in: 5.3.38.Final (5.3 maintenance branch) and Hibernate 6.x. NOT fixed on the 5.6 line — no 5.6.16 was released. GHSA-2p5w-cvg5-gc5c lists affected >=5.2.8 <=5.6.15 with 'patched: None' and no commit link."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-0603",
      "aliases" : [ "GHSA-2p5w-cvg5-gc5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.hibernate/hibernate-core@5.5.9.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.hibernate/hibernate-core@5.5.9.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "172fb1b85d984035bd46d60e55e2f8acc20ebac024068b6e1b109faae2d617a8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-0603 fixed by backporting the upstream fix onto the 5.5.9.Final baseline. Fixed upstream in: 5.3.38.Final (5.3 maintenance branch) and Hibernate 6.x. NOT fixed on the 5.6 line — no 5.6.16 was released. GHSA-2p5w-cvg5-gc5c lists affected >=5.2.8 <=5.6.15 with 'patched: None' and no commit link."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-0603",
      "aliases" : [ "GHSA-2p5w-cvg5-gc5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.hibernate/hibernate-core@5.6.15.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.hibernate/hibernate-core@5.6.15.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "513ec0063b66896276457d9baed91076824c6e501b6ed098aaae5ad185094b42"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-0603 fixed by backporting the upstream fix onto the 5.6.15.Final baseline. Fixed upstream in: 5.3.38.Final (5.3 maintenance branch) and Hibernate 6.x. NOT fixed on the 5.6 line — no 5.6.16 was released. GHSA-2p5w-cvg5-gc5c lists affected >=5.2.8 <=5.6.15 with 'patched: None' and no commit link."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-27820",
      "aliases" : [ "GHSA-73m2-qfq3-56cx" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.4.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6589c7aac8c5f15d05c49d6b26588fe43e3930aed49d75cddc57284a9c02ada1"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-27820 fixed by backporting the upstream fix onto the 5.4.1 baseline. Fixed upstream in: 5.4.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-9096",
      "aliases" : [ "GHSA-86p9-x5pw-94qx" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.lowagie/itext@2.1.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.lowagie/itext@2.1.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "269001a170208f904c131c9de5adfd854ac36392120af3ff52dff09fde159f87"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-9096 fixed by a patch applied onto the 2.1.7 baseline; no upstream release carries this fix. Upstream status: none. iText Group fixed it in com.itextpdf:itextpdf 5.5.12 / itext7 7.0.3, which is a different groupId AND an AGPL relicense, so it cannot be used in an MPL/LGPL artifact. Nothing on the com.lowagie:itext coordinate, and nothing in itext/itextpdf history, ever fixed it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "97705509e09a9026520e55205d87dfc77c9ac3c05da8e4b839dd33a9770e21e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.10.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "97705509e09a9026520e55205d87dfc77c9ac3c05da8e4b839dd33a9770e21e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.10.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-42003",
      "aliases" : [ "GHSA-jjjh-jjxp-wpff" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "97705509e09a9026520e55205d87dfc77c9ac3c05da8e4b839dd33a9770e21e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-42003 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.12.7.1 / 2.13.4.2 — no 2.10.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-42004",
      "aliases" : [ "GHSA-rgv9-q543-rqg4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "97705509e09a9026520e55205d87dfc77c9ac3c05da8e4b839dd33a9770e21e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-42004 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.12.7.1 / 2.13.4 — no 2.10.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-46877",
      "aliases" : [ "GHSA-3x8x-79m2-3w2w" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.10.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "97705509e09a9026520e55205d87dfc77c9ac3c05da8e4b839dd33a9770e21e3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-46877 fixed by backporting the upstream fix onto the 2.10.5.1 baseline. Fixed upstream in: 2.12.6 / 2.13.1 — no 2.10.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b0dc30ffc6d6395ad163c05ec9e9508d0945c66058f98a22fd1f2eb5c2ed63ed"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.11.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b0dc30ffc6d6395ad163c05ec9e9508d0945c66058f98a22fd1f2eb5c2ed63ed"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.11.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b0dc30ffc6d6395ad163c05ec9e9508d0945c66058f98a22fd1f2eb5c2ed63ed"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.11.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.11.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b0dc30ffc6d6395ad163c05ec9e9508d0945c66058f98a22fd1f2eb5c2ed63ed"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.11.4 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.11.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "08cd8c5a5a25d28ccab330565bed6adc3450548c4ae362e4fa0837bbbd2d926e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.12.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "08cd8c5a5a25d28ccab330565bed6adc3450548c4ae362e4fa0837bbbd2d926e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.12.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "08cd8c5a5a25d28ccab330565bed6adc3450548c4ae362e4fa0837bbbd2d926e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.12.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.12.7.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "08cd8c5a5a25d28ccab330565bed6adc3450548c4ae362e4fa0837bbbd2d926e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.12.7.2 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.12.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6ea19c923ef338b36dafea516a296c26d4a6189247b0fe26ceb58c1051829a19"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.13.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6ea19c923ef338b36dafea516a296c26d4a6189247b0fe26ceb58c1051829a19"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.13.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-50193",
      "aliases" : [ "GHSA-3wrr-7qpf-2prh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6ea19c923ef338b36dafea516a296c26d4a6189247b0fe26ceb58c1051829a19"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-50193 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.14.0 — no 2.13.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6ea19c923ef338b36dafea516a296c26d4a6189247b0fe26ceb58c1051829a19"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.13.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6ea19c923ef338b36dafea516a296c26d4a6189247b0fe26ceb58c1051829a19"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.13.5 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.13.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3020826bc1dada8cfe359483fe7dca73f2886acfefc523df1b0b6f92c1d33a25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.14.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3020826bc1dada8cfe359483fe7dca73f2886acfefc523df1b0b6f92c1d33a25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.14.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3020826bc1dada8cfe359483fe7dca73f2886acfefc523df1b0b6f92c1d33a25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.14.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.14.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3020826bc1dada8cfe359483fe7dca73f2886acfefc523df1b0b6f92c1d33a25"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.14.3 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.14.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "0877c2cccaaecc20b5f6d554d157f3be20213cb3da8956562ee6757f159df92e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.15.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "0877c2cccaaecc20b5f6d554d157f3be20213cb3da8956562ee6757f159df92e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.15.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "0877c2cccaaecc20b5f6d554d157f3be20213cb3da8956562ee6757f159df92e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.15.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "0877c2cccaaecc20b5f6d554d157f3be20213cb3da8956562ee6757f159df92e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.15.4 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.15.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d3ce711a0d0cf51ad3e087b11b02cd2cb8323a8d82100b064c3aa64c647c2211"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.16.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d3ce711a0d0cf51ad3e087b11b02cd2cb8323a8d82100b064c3aa64c647c2211"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.16.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d3ce711a0d0cf51ad3e087b11b02cd2cb8323a8d82100b064c3aa64c647c2211"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.16.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.16.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d3ce711a0d0cf51ad3e087b11b02cd2cb8323a8d82100b064c3aa64c647c2211"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.16.2 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.16.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bf0d0046dbb678ac1640a9bb7c209f31efc0317baef4119acd7f33edbf4a633b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.17.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bf0d0046dbb678ac1640a9bb7c209f31efc0317baef4119acd7f33edbf4a633b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.17.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bf0d0046dbb678ac1640a9bb7c209f31efc0317baef4119acd7f33edbf4a633b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.17.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bf0d0046dbb678ac1640a9bb7c209f31efc0317baef4119acd7f33edbf4a633b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.17.3 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.17.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3e601802b3b6b2606041f836b1297a00c95387c63b3ae33bb5d3d0f90449016d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.19.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3e601802b3b6b2606041f836b1297a00c95387c63b3ae33bb5d3d0f90449016d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.19.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3e601802b3b6b2606041f836b1297a00c95387c63b3ae33bb5d3d0f90449016d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.19.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.19.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3e601802b3b6b2606041f836b1297a00c95387c63b3ae33bb5d3d0f90449016d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.19.4 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.19.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54512",
      "aliases" : [ "GHSA-j3rv-43j4-c7qm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45465f2fa27e49b10c8bee2622c3c966f24e0bc180a665537d9afeb37c0b6fc0"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54512 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.20.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54513",
      "aliases" : [ "GHSA-rmj7-2vxq-3g9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45465f2fa27e49b10c8bee2622c3c966f24e0bc180a665537d9afeb37c0b6fc0"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54513 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.20.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54514",
      "aliases" : [ "GHSA-hgj6-7826-r7m5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45465f2fa27e49b10c8bee2622c3c966f24e0bc180a665537d9afeb37c0b6fc0"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54514 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.8 / 2.21.4 — no 2.20.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-54515",
      "aliases" : [ "GHSA-5jmj-h7xm-6q6v" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "45465f2fa27e49b10c8bee2622c3c966f24e0bc180a665537d9afeb37c0b6fc0"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-54515 fixed by backporting the upstream fix onto the 2.20.2 baseline. Fixed upstream in: 2.18.9 / 2.21.5 / 2.22.1 — no 2.20.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-36518",
      "aliases" : [ "GHSA-57j2-w4cx-62h2" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.10.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.10.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "be8dbd4e97554632e45e525cc7d949fa7667edc1902b8ea65636b54231ea1daf"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-36518 fixed by backporting the upstream fix onto the 2.9.10.8 baseline. Fixed upstream in: 2.12.6.1 / 2.13.2.1 / 2.14.0 (no 2.9.x line fix — 2.9 was EOL)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-10202",
      "aliases" : [ "GHSA-c27h-mcmw-48hv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e95be7c730672b27aa601fc74f8814e18d23eced61511700caad43010c938685"
      }
    }, {
      "@id" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "48081f92d7f5afdb2e01fe0a684f5c3835b7bfddb6413b0ff9dc93a55dd77d36"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-10202 fixed by a patch applied onto the 1.9.13 baseline; no upstream release carries this fix. Upstream status: none — fixed in the FasterXML/jackson-1 master tree (9ac68db8, Dec 2017) but never released to Central; 1.9.13 (Jul 2013) is the last and final 1.x release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-10172",
      "aliases" : [ "GHSA-r6j9-8759-g62w" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.codehaus.jackson/jackson-core-asl@1.9.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e95be7c730672b27aa601fc74f8814e18d23eced61511700caad43010c938685"
      }
    }, {
      "@id" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.codehaus.jackson/jackson-mapper-asl@1.9.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "48081f92d7f5afdb2e01fe0a684f5c3835b7bfddb6413b0ff9dc93a55dd77d36"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-10172 fixed by a patch applied onto the 1.9.13 baseline; no upstream release carries this fix. Upstream status: none — fixed in the FasterXML/jackson-1 master tree (54c6bc36, 2361ec46, Jul 2016) but never released to Central."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-10492",
      "aliases" : [ "GHSA-7c3f-cg9x-f3gr" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "978ca114f6fe24ab5f17d87a4942408880612b2690699184164ddfc9abc87362"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-10492 fixed by backporting the upstream fix onto the 6.21.5 baseline. Fixed upstream in: 7.0.4"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-6009",
      "aliases" : [ "GHSA-9wxq-mwqw-8hhg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/net.sf.jasperreports/jasperreports@6.21.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "978ca114f6fe24ab5f17d87a4942408880612b2690699184164ddfc9abc87362"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-6009 fixed by backporting the upstream fix onto the 6.21.5 baseline. Fixed upstream in: 7.0.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "317ef4ed2720e81ad94bae13b9fbc9b36fd74316d0cd4e01db977b7e358ee09f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.2.10.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.jboss.netty/netty@3.2.10.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "317ef4ed2720e81ad94bae13b9fbc9b36fd74316d0cd4e01db977b7e358ee09f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.2.10.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-33813",
      "aliases" : [ "BIT-solr-2021-33813", "GHSA-2363-cqg2-863c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.jdom/jdom@1.1.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.jdom/jdom@1.1.3%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-33813 fixed by a patch applied onto the 1.1.3 baseline; no upstream release carries this fix. Upstream status: none for org.jdom:jdom — upstream fixed it only on the org.jdom:jdom2 coordinate, in 2.0.6.1 (2021-10). 1.1.3 (2012-02) is the last and final 1.x release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-8184",
      "aliases" : [ "GHSA-g8m5-722r-8whq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "07960e95fffea272bb1a77cdb2f7e6ace61fbde56533b28d6bca4755c01aa4ca"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-8184 fixed by backporting the upstream fix onto the 9.3.30.v20211001 baseline. Fixed upstream in: 9.4.56.v20240826 / 10.0.24 / 11.0.24 / 12.0.9"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-26048",
      "aliases" : [ "GHSA-qw69-rqj8-6qw8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.3.30.v20211001%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "07960e95fffea272bb1a77cdb2f7e6ace61fbde56533b28d6bca4755c01aa4ca"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-26048 fixed by backporting the upstream fix onto the 9.3.30.v20211001 baseline. Fixed upstream in: 9.4.51.v20230217 / 10.0.14 / 11.0.14"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-2332",
      "aliases" : [ "GHSA-355h-qmc2-wpwf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.4.58.v20250814%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.4.58.v20250814%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c6b04799b0b563e0cc0574e0fc4ec67b970941343b8da9521495e8baed7a4a18"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-2332 fixed by backporting the upstream fix onto the 9.4.58.v20250814 baseline. Fixed upstream in: 12.0.33 / 12.1.7 (public). 9.4.60/10.0.28/11.0.28 are Webtide commercial-only and never shipped to Maven Central; 9.4.60 has no upstream git tag and 404s on Central."
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e62c81d23340e4cc16059435e504c6d128169e21ca1068568844869ffa326be5"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7f7820402ac6ebb9101545fe781cc9a19f69028756cfb66e0735d4bfbc5bef05"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.0.2.v20100331 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.0.2.v20100331%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e62c81d23340e4cc16059435e504c6d128169e21ca1068568844869ffa326be5"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.0.2.v20100331%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7f7820402ac6ebb9101545fe781cc9a19f69028756cfb66e0735d4bfbc5bef05"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.0.2.v20100331 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4cc488a39ec4b8b5584ce958360d830e7fbbd5a0c9260c01d7272d192fde5fc6"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f32206bc6d61f266ec684cb9f8a82504df927ec5a8be7eb93220f02de423202f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.1.6.v20100715 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.1.6.v20100715%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4cc488a39ec4b8b5584ce958360d830e7fbbd5a0c9260c01d7272d192fde5fc6"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.1.6.v20100715%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f32206bc6d61f266ec684cb9f8a82504df927ec5a8be7eb93220f02de423202f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.1.6.v20100715 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f6d8433db4f9d63d72e97d2650a72de884158bdc6b248aafd3b2ef2887ccae59"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f1d826b6ba591bf07810a14f999e336559719fa2063bca86431f13f8be8ad112"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.2.2.v20101205 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.2.2.v20101205%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f6d8433db4f9d63d72e97d2650a72de884158bdc6b248aafd3b2ef2887ccae59"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.2.2.v20101205%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f1d826b6ba591bf07810a14f999e336559719fa2063bca86431f13f8be8ad112"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.2.2.v20101205 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "35f686b6004708b2ade2619df437d30cf37bd3dd69a42d3e9f9f8623ce33f5b7"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3974578dd1495ccd2a76532f08b77af37b4877f8eb3956d119ae0ceec311821f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.3.1.v20110307 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.3.1.v20110307%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "35f686b6004708b2ade2619df437d30cf37bd3dd69a42d3e9f9f8623ce33f5b7"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.3.1.v20110307%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3974578dd1495ccd2a76532f08b77af37b4877f8eb3956d119ae0ceec311821f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.3.1.v20110307 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "abfdd834b0f4d5643fb020b421aa38aa7ae23ceafa4f3142481207ded660db70"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9541a02fbb8c3dbf1edd02fab0173479d8781d37ea68deeef7f2ced4657f929e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.4.5.v20110725 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.4.5.v20110725%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "abfdd834b0f4d5643fb020b421aa38aa7ae23ceafa4f3142481207ded660db70"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.4.5.v20110725%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9541a02fbb8c3dbf1edd02fab0173479d8781d37ea68deeef7f2ced4657f929e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.4.5.v20110725 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "a3bb449e9165a972619d842b5a15306b51422b4e3b328aff8d3f9a39baa0a76c"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c57351a797ea97077e1df7a1f6a9430422069fd70e9b48f5271269f8a61d2c71"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.5.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.5.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "a3bb449e9165a972619d842b5a15306b51422b4e3b328aff8d3f9a39baa0a76c"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.5.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c57351a797ea97077e1df7a1f6a9430422069fd70e9b48f5271269f8a61d2c71"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.5.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d3e68187be34d8d20cd9293327d60b0fbc667bc165108a2b8d00588704d49124"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2e0d7175868d9021592708493b92bfb1c77d225808d0343e46d6c72b764ff419"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 7.6.21.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@7.6.21.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d3e68187be34d8d20cd9293327d60b0fbc667bc165108a2b8d00588704d49124"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@7.6.21.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2e0d7175868d9021592708493b92bfb1c77d225808d0343e46d6c72b764ff419"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 7.6.21.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1071c69d041fd2f63d530efd2cd6030992991c4d45fb08af6b21c9f0f0f7b668"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4c2a9adf62c2f17063a05756d0c3d9a7d5be9e63857b09ed8140a694def9135a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.0.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.0.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1071c69d041fd2f63d530efd2cd6030992991c4d45fb08af6b21c9f0f0f7b668"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.0.4.v20111024%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4c2a9adf62c2f17063a05756d0c3d9a7d5be9e63857b09ed8140a694def9135a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.0.4.v20111024 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "9f47afe18b2c932d5120c08c94ad0bb96ba036196db8a7af6a631cea6e7fa915"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c344cc8c477c0bf401dc5bd813eb0ae2ead0f839a5a539b00cfad12248b6fb01"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.1.22.v20160922 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.1.22.v20160922%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "9f47afe18b2c932d5120c08c94ad0bb96ba036196db8a7af6a631cea6e7fa915"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.1.22.v20160922%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c344cc8c477c0bf401dc5bd813eb0ae2ead0f839a5a539b00cfad12248b6fb01"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.1.22.v20160922 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c4be6e36befc7a521bf13872aef18335f99489fbf8242540ddc0c76fd941e200"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c6f1b6cea4ae4385953e405388aa2fd9bf38081e26dd5364e0e1256259497863"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 8.2.0.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@8.2.0.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c4be6e36befc7a521bf13872aef18335f99489fbf8242540ddc0c76fd941e200"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@8.2.0.v20160908%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c6f1b6cea4ae4385953e405388aa2fd9bf38081e26dd5364e0e1256259497863"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 8.2.0.v20160908 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f7234c1d7d9b4b69139f0c29af2f830fa03e9b8a22d797086c6b01f3b3981f1a"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ee027f05889a7ff7ac4e757ae1e890178f7b16a33ebc0bba77f1e185f85997cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f7234c1d7d9b4b69139f0c29af2f830fa03e9b8a22d797086c6b01f3b3981f1a"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ee027f05889a7ff7ac4e757ae1e890178f7b16a33ebc0bba77f1e185f85997cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7656",
      "aliases" : [ "GHSA-84q7-p226-4x5w" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f7234c1d7d9b4b69139f0c29af2f830fa03e9b8a22d797086c6b01f3b3981f1a"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ee027f05889a7ff7ac4e757ae1e890178f7b16a33ebc0bba77f1e185f85997cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7656 fixed by backporting the upstream fix onto the 9.0.7.v20131107 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-2080",
      "aliases" : [ "GHSA-ghgj-3xqr-6jfm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f7234c1d7d9b4b69139f0c29af2f830fa03e9b8a22d797086c6b01f3b3981f1a"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.0.7.v20131107%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ee027f05889a7ff7ac4e757ae1e890178f7b16a33ebc0bba77f1e185f85997cb"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "All 33 BadMessage sites at 9.0.7 pass a bare status or a compile-time constant; the buffer-carrying message JetLeak leaks arrived in 9.2.3."
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7657",
      "aliases" : [ "GHSA-vgg8-72f2-qm23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eeb1403ef41a88fc7e2e9b805efd37e926a82bce199c4674400bef08a4e808a6"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "faab9e7e7e1d8bc4d2077c814b450dbe11cf1e572b12e2673627eb0b942a45cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7657 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7658",
      "aliases" : [ "GHSA-6x9x-8qw9-9pp6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eeb1403ef41a88fc7e2e9b805efd37e926a82bce199c4674400bef08a4e808a6"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "faab9e7e7e1d8bc4d2077c814b450dbe11cf1e572b12e2673627eb0b942a45cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7658 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2017-7656",
      "aliases" : [ "GHSA-84q7-p226-4x5w" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eeb1403ef41a88fc7e2e9b805efd37e926a82bce199c4674400bef08a4e808a6"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "faab9e7e7e1d8bc4d2077c814b450dbe11cf1e572b12e2673627eb0b942a45cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2017-7656 fixed by backporting the upstream fix onto the 9.1.6.v20160112 baseline. Fixed upstream in: 9.2.25.v20180606 / 9.3.24.v20180605 / 9.4.11.v20180605"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-2080",
      "aliases" : [ "GHSA-ghgj-3xqr-6jfm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-http@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eeb1403ef41a88fc7e2e9b805efd37e926a82bce199c4674400bef08a4e808a6"
      }
    }, {
      "@id" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.eclipse.jetty/jetty-server@9.1.6.v20160112%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "faab9e7e7e1d8bc4d2077c814b450dbe11cf1e572b12e2673627eb0b942a45cb"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "All 28 BadMessage sites at 9.1.6 pass a bare status or a compile-time constant; the buffer-carrying message JetLeak leaks arrived in 9.2.3."
  }, {
    "vulnerability" : {
      "name" : "CVE-2018-21234",
      "aliases" : [ "GHSA-jrg3-qq99-35g7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2018-21234 fixed by backporting the upstream fix onto the 5.0.3 baseline. Fixed upstream in: 5.0.4"
  }, {
    "vulnerability" : {
      "name" : "CVE-2018-21234",
      "aliases" : [ "GHSA-jrg3-qq99-35g7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.jodd/jodd-json@5.0.3%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2018-21234 fixed by backporting the upstream fix onto the 5.0.3 baseline. Fixed upstream in: 5.0.4"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-1370",
      "aliases" : [ "GHSA-493p-pfq6-5258" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/net.minidev/json-smart@1.3.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/net.minidev/json-smart@1.3.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ea6fdf67d09437293993a25b4c74db1eaca7132de056147ebf83ca786afa8b68"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-1370 fixed by backporting the upstream fix onto the 1.3.3 baseline. Fixed upstream in: 2.4.9 (2.x line only; 1.x never fixed)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-35554",
      "aliases" : [ "GHSA-5qcv-4rpc-jp93" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.kafka/kafka-clients@2.8.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.kafka/kafka-clients@2.8.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7511fb9f9dc9275b74ad013b12f14f747db3754e9cf0439815f2eb89d050c3e5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-35554 fixed by backporting the upstream fix onto the 2.8.2 baseline. Fixed upstream in: 3.9.2 (also 4.0.2 / 4.1.2 / 4.2.0) — nothing was ever released on the 2.x line"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-27817",
      "aliases" : [ "BIT-kafka-2025-27817", "GHSA-vgq5-3255-v292" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.kafka/kafka-clients@3.2.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.2.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eb39508e6fd91cda99402dbe3f749bbef1623262b753dbc4b422df6251530c8f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-27817 fixed by backporting the upstream fix onto the 3.2.3 baseline. Fixed upstream in: 3.9.1 (also 4.0.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-35554"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-35554 fixed by backporting the upstream fix onto the 3.8.1 baseline. Fixed upstream in: 3.9.2 (also 4.0.2 / 4.1.2 / 4.2.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-35554",
      "aliases" : [ "GHSA-5qcv-4rpc-jp93" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "db92fcdd7330add6a82cabfad0028e96ab1c5bb530e0e4821d029c151197c50f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-35554 fixed by backporting the upstream fix onto the 3.8.1 baseline. Fixed upstream in: 3.9.2 (also 4.0.2 / 4.1.2 / 4.2.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-27818",
      "aliases" : [ "BIT-kafka-2025-27818", "GHSA-76qp-h5mr-frr4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.kafka/kafka-clients@3.8.1%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "db92fcdd7330add6a82cabfad0028e96ab1c5bb530e0e4821d029c151197c50f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-27818 fixed by backporting the upstream fix onto the 3.8.1 baseline. Fixed upstream in: 3.9.1 (also 4.0.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-17571",
      "aliases" : [ "GHSA-2qrg-x229-3v8q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-17571 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.0 (ch.qos.reload4j — different coordinate; never shipped as log4j:log4j)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-23305",
      "aliases" : [ "GHSA-65fg-84f6-3jq3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-23305 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.2 (removed in .18.1, restored via PreparedStatement in .18.2)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-23302",
      "aliases" : [ "GHSA-w9p3-5cr8-m3jj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-23302 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-4104",
      "aliases" : [ "GHSA-fp5r-v3w9-4333" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-4104 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-23307",
      "aliases" : [ "GHSA-f7vh-qwp3-x37m" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-23307 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.18.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-26464",
      "aliases" : [ "GHSA-vp98-w2p3-mv35" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/log4j/log4j@1.2.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7676cb0c00fb1fa3de1f71cc66858663a5e01fdfd194b50be539939ee0c1dc07"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-26464 fixed by backporting the upstream fix onto the 1.2.17 baseline. Fixed upstream in: reload4j 1.2.25 (issue 53 — confirm the issue-53↔CVE-2023-26464 mapping before asserting scanner coverage)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-44228",
      "aliases" : [ "GHSA-jfh8-c2jp-5v3q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-44228 fixed by backporting the upstream fix onto the 2.14.1 baseline. Fixed upstream in: 2.15.0 (message lookups off) / completed in 2.16.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-45046",
      "aliases" : [ "GHSA-7rjr-3q55-vv33" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-45046 fixed by backporting the upstream fix onto the 2.14.1 baseline. Fixed upstream in: 2.16.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-45105",
      "aliases" : [ "GHSA-p6xc-xr62-6r2g" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-45105 fixed by backporting the upstream fix onto the 2.14.1 baseline. Fixed upstream in: 2.17.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-12801",
      "aliases" : [ "GHSA-6v67-2wr5-gvf4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "42f9c82ec0cdcd8bfd128a86ae87061f99f44f72881c81b2e3e26da84dacbb29"
      }
    }, {
      "@id" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "987f0b3e8380374d17b55bfe8266c522c1f01030e2b5a34fa37adad9b58044e4"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-12801 fixed by backporting the upstream fix onto the 1.1.11 baseline. Fixed upstream in: 1.3.15 / 1.5.13"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-11226",
      "aliases" : [ "GHSA-25qh-j22f-pwp8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-core@1.1.11%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "42f9c82ec0cdcd8bfd128a86ae87061f99f44f72881c81b2e3e26da84dacbb29"
      }
    }, {
      "@id" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-classic@1.1.11%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "987f0b3e8380374d17b55bfe8266c522c1f01030e2b5a34fa37adad9b58044e4"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-11226 fixed by backporting the upstream fix onto the 1.1.11 baseline. Fixed upstream in: 1.3.16 / 1.5.19"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-12801",
      "aliases" : [ "GHSA-6v67-2wr5-gvf4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "da8be16ce83b23528ff70af8bfb9fbfad3acdba1f7c576d5737061e9192ca597"
      }
    }, {
      "@id" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "a536bda8dcfb8403c41e0ec43f2cf99d1d3d77dc09479f680ec795b2436dcbba"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-12801 fixed by backporting the upstream fix onto the 1.2.13 baseline. Fixed upstream in: 1.3.15 / 1.5.13"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-11226",
      "aliases" : [ "GHSA-25qh-j22f-pwp8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-core@1.2.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "da8be16ce83b23528ff70af8bfb9fbfad3acdba1f7c576d5737061e9192ca597"
      }
    }, {
      "@id" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/ch.qos.logback/logback-classic@1.2.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "a536bda8dcfb8403c41e0ec43f2cf99d1d3d77dc09479f680ec795b2436dcbba"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-11226 fixed by backporting the upstream fix onto the 1.2.13 baseline. Fixed upstream in: 1.3.16 / 1.5.19"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-52046",
      "aliases" : [ "GHSA-76h9-2vwh-w278" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5d2094046ae445bd4e07b0ca0a395dc10e3857ca9ff456b0085a0a7bfec12e0e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-52046 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.27, 2.1.10, 2.2.4"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-52046",
      "aliases" : [ "GHSA-76h9-2vwh-w278" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "0eb491942e7dc3e1d76b375d09a1a6b5c4e3e25ab2a6bb21627afbe986deb4d5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-52046 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.27, 2.1.10, 2.2.4"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41409",
      "aliases" : [ "GHSA-f2wh-grmh-r6jm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "0eb491942e7dc3e1d76b375d09a1a6b5c4e3e25ab2a6bb21627afbe986deb4d5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41409 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.28 / 2.1.11 / 2.2.6"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41635",
      "aliases" : [ "GHSA-8297-v2rf-2p32" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "0eb491942e7dc3e1d76b375d09a1a6b5c4e3e25ab2a6bb21627afbe986deb4d5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41635 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.28 / 2.1.11 / 2.2.6"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-47065",
      "aliases" : [ "GHSA-v3pr-hxpr-mfm8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.mina/mina-core@2.0.25%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "0eb491942e7dc3e1d76b375d09a1a6b5c4e3e25ab2a6bb21627afbe986deb4d5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-47065 fixed by backporting the upstream fix onto the 2.0.25 baseline. Fixed upstream in: 2.0.29 / 2.1.13 / 2.2.8"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f4087724fd63dacaacb31d3311a866ad5016f6856605925b3ed2594bec5df6ef"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f4087724fd63dacaacb31d3311a866ad5016f6856605925b3ed2594bec5df6ef"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f4087724fd63dacaacb31d3311a866ad5016f6856605925b3ed2594bec5df6ef"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.3.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f4087724fd63dacaacb31d3311a866ad5016f6856605925b3ed2594bec5df6ef"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.3.1.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "09ce60b9e114e93ff7a99a92e7ca91013cf1bdd1efb32ba95190d353026a9b89"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "09ce60b9e114e93ff7a99a92e7ca91013cf1bdd1efb32ba95190d353026a9b89"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "09ce60b9e114e93ff7a99a92e7ca91013cf1bdd1efb32ba95190d353026a9b89"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.4.6.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "09ce60b9e114e93ff7a99a92e7ca91013cf1bdd1efb32ba95190d353026a9b89"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.4.6.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9566f409876e57fda57ad23e01c4a57f2d7914d9f2cde2850db76036eb9e21a9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9566f409876e57fda57ad23e01c4a57f2d7914d9f2cde2850db76036eb9e21a9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9566f409876e57fda57ad23e01c4a57f2d7914d9f2cde2850db76036eb9e21a9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.5.13.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9566f409876e57fda57ad23e01c4a57f2d7914d9f2cde2850db76036eb9e21a9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.5.13.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e97f1e3bebf006678f45f25953d4385c6941e42ce16723370f44ccfc5932c7fc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e97f1e3bebf006678f45f25953d4385c6941e42ce16723370f44ccfc5932c7fc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e97f1e3bebf006678f45f25953d4385c6941e42ce16723370f44ccfc5932c7fc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.6.10.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e97f1e3bebf006678f45f25953d4385c6941e42ce16723370f44ccfc5932c7fc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.6.10.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cb8d7329e400ad42a6aaa3c88adaa7567b8fde57b9535e098145c328e8fe03c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cb8d7329e400ad42a6aaa3c88adaa7567b8fde57b9535e098145c328e8fe03c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cb8d7329e400ad42a6aaa3c88adaa7567b8fde57b9535e098145c328e8fe03c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.7.1.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cb8d7329e400ad42a6aaa3c88adaa7567b8fde57b9535e098145c328e8fe03c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.7.1.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e8669366a59e0ec5ef8e3356671fe24e261a574d23b2317f06e1fb10d8566edd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e8669366a59e0ec5ef8e3356671fe24e261a574d23b2317f06e1fb10d8566edd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e8669366a59e0ec5ef8e3356671fe24e261a574d23b2317f06e1fb10d8566edd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.8.3.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e8669366a59e0ec5ef8e3356671fe24e261a574d23b2317f06e1fb10d8566edd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.8.3.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d1d9eb8e48699af918de7fd9f8f45130658cd29f3f603149a810e26d1d48e9be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d1d9eb8e48699af918de7fd9f8f45130658cd29f3f603149a810e26d1d48e9be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d1d9eb8e48699af918de7fd9f8f45130658cd29f3f603149a810e26d1d48e9be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.44"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.9.9.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d1d9eb8e48699af918de7fd9f8f45130658cd29f3f603149a810e26d1d48e9be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.9.9.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-7238",
      "aliases" : [ "GHSA-ff2w-cq2g-wv5f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-7238",
      "aliases" : [ "GHSA-ff2w-cq2g-wv5f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-7238",
      "aliases" : [ "GHSA-ff2w-cq2g-wv5f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.003"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "a9b46a001c4ab98d2701b438cc98e020bb39219a98a201f7b9d97130e4457e66"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "a9b46a001c4ab98d2701b438cc98e020bb39219a98a201f7b9d97130e4457e66"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-43797",
      "aliases" : [ "GHSA-wx5j-54mm-rqqq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "a9b46a001c4ab98d2701b438cc98e020bb39219a98a201f7b9d97130e4457e66"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-43797 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.71.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20445",
      "aliases" : [ "GHSA-p2v9-g2qv-p635" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "a9b46a001c4ab98d2701b438cc98e020bb39219a98a201f7b9d97130e4457e66"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20445 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.44"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-7238",
      "aliases" : [ "GHSA-ff2w-cq2g-wv5f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty@3.10.6.Final%2Bbackpatch.004"
      },
      "hashes" : {
        "sha-256" : "a9b46a001c4ab98d2701b438cc98e020bb39219a98a201f7b9d97130e4457e66"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-7238 fixed by backporting the upstream fix onto the 3.10.6.Final baseline. Fixed upstream in: 4.1.46"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-16869",
      "aliases" : [ "GHSA-p979-4mfw-53vg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8cc5a71a814fbdb04f4763a97340092c2bdf081dc88a68a25d47152502aab210"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "2982f0c81ee47f0c2dcbd0e421a5c9d35fc3f64dc7843ef389ac8bbc451347d9"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "f2fb68f12917dc0c92917765510f0e727ff1a14559369839d3e6869f2ad44838"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "dca7c63a502e4f8ab50e83c235ea11895b9c0944a783f133c669c73343446a32"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "e9a225f2e2976dd59dc7f1ff0a91cd60b24a1fc85595ed2cc073759691c2aff5"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "b4e817f1d0f7b8c76804ba61a7a00018e18d85bed9c0e01c2f29557186199327"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-16869 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.42.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-20444",
      "aliases" : [ "GHSA-cqqj-4p63-rrmm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-common@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8cc5a71a814fbdb04f4763a97340092c2bdf081dc88a68a25d47152502aab210"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-buffer@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "2982f0c81ee47f0c2dcbd0e421a5c9d35fc3f64dc7843ef389ac8bbc451347d9"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-transport@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "f2fb68f12917dc0c92917765510f0e727ff1a14559369839d3e6869f2ad44838"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-codec@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "dca7c63a502e4f8ab50e83c235ea11895b9c0944a783f133c669c73343446a32"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-handler@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "e9a225f2e2976dd59dc7f1ff0a91cd60b24a1fc85595ed2cc073759691c2aff5"
      }
    }, {
      "@id" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/io.netty/netty-codec-http@4.0.56.Final%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "b4e817f1d0f7b8c76804ba61a7a00018e18d85bed9c0e01c2f29557186199327"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-20444 fixed by backporting the upstream fix onto the 4.0.56.Final baseline. Fixed upstream in: 4.1.44.Final"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-0341",
      "aliases" : [ "GHSA-3cqm-mf7h-prrj", "A-171980069", "ASB-A-171980069" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.squareup.okhttp3/okhttp@3.14.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.squareup.okhttp3/okhttp@3.14.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "602bfd71edc172a430ec4e7790c0c2456fedad1d0c0fa59c814543841194ec18"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-0341 fixed by backporting the upstream fix onto the 3.14.9 baseline. Fixed upstream in: 4.9.2 (Kotlin 4.x line only — no 3.x release ever carried the fix)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.0.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.0.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2bd522b9b968f446c2f06d8c63cd6825dd59101c9547bbcd8ee3a4d28a104637"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.0.2 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.1.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.1.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3cb21227d7a267a66f1a0a480fc4c1765e0ddd3b4f02b422f5cb848bf94fe67d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.1.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.2.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.2.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "64677f501bc18ffd01c35e36bbcc7bca3a40ccaa0f3fb7d2678217980e118db2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.2.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.3.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.3.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "36f8c29ef237249424f17bc64b20c473942e61fc56b221d0ca4b7ef27dd81c0d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.3.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.4.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.4.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "27c4f940e8a05fb70f6d1d9d015f75ee9aeaef83e0724bbbc6d053f4df397211"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.4.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "384d4df998af24ebad320c6f74b6441aef5ef95ed84162156821f5733d02e980"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.5.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.6.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.6.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4b35049110d46d46031b880348136e1e0d29791d19c0de8227fc5ede7b82c3df"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.6.1 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.7.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.7.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d2a217bbdcde38f2f29212a1878826c2bb7afa68d2c02e853434c0a9380a41e5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.7.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.8.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.8.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "24ff5074509553ff0f46f4f856cdb688363e3d3f7014c712667bd433e7b1587f"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.8.3 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.9.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-25581",
      "aliases" : [ "GHSA-76mw-6p95-x9x5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.pac4j/pac4j-core@3.9.0%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "f1f81cbf3b362e05414017d50d6f5689bfaa31379784a230660606051dd8d9a1"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-25581 fixed by backporting the upstream fix onto the 3.9.0 baseline. Fixed upstream in: 4.1.0 (removed InternalAttributeHandler entirely; 4.x is a breaking major. Advisories say 4.0.0 but the class is verifiably still present in 4.0.0 and gone in 4.1.0)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-44228",
      "aliases" : [ "GHSA-jfh8-c2jp-5v3q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "fa17ce86419aae6092603159bea747fc17806ee048d1b6499e05b64c6a713b1c"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-44228 fixed by backporting the upstream fix onto the 1.8.7 baseline. Fixed upstream in: 1.9.2 / 1.10.8 / 1.11.10 / 2.0.11"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-45046",
      "aliases" : [ "GHSA-7rjr-3q55-vv33" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "fa17ce86419aae6092603159bea747fc17806ee048d1b6499e05b64c6a713b1c"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-45046 fixed by backporting the upstream fix onto the 1.8.7 baseline. Fixed upstream in: 1.9.2 / 1.10.8 / 1.11.11 / 2.0.12"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-45105",
      "aliases" : [ "GHSA-p6xc-xr62-6r2g" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.ops4j.pax.logging/pax-logging-log4j2@1.8.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "fa17ce86419aae6092603159bea747fc17806ee048d1b6499e05b64c6a713b1c"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-45105 fixed by backporting the upstream fix onto the 1.8.7 baseline. Fixed upstream in: 1.9.2 / 1.10.9 / 1.11.12 / 2.0.13"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-12415",
      "aliases" : [ "GHSA-9jwc-q6j3-8g9g" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.poi/poi-ooxml@3.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.poi/poi-ooxml@3.17%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-12415 fixed by backporting the upstream fix onto the 3.17 baseline. Fixed upstream in: 4.1.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-1597",
      "aliases" : [ "BIT-postgresql-jdbc-driver-2024-1597", "GHSA-24rp-q3w6-vc56" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-1597 fixed by backporting the upstream fix onto the 42.4.0 baseline. Fixed upstream in: 42.4.4 (also 42.2.28 / 42.3.9 / 42.5.5 / 42.6.1 / 42.7.2)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-31197",
      "aliases" : [ "BIT-postgresql-jdbc-driver-2022-31197", "GHSA-r38f-c4h4-hqq2" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.postgresql/postgresql@42.4.0%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-31197 fixed by backporting the upstream fix onto the 42.4.0 baseline. Fixed upstream in: 42.4.1 (also 42.2.26 / 42.3.7)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-1597",
      "aliases" : [ "BIT-postgresql-jdbc-driver-2024-1597", "GHSA-24rp-q3w6-vc56" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.postgresql/postgresql@9.4.1212.jre7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.postgresql/postgresql@9.4.1212.jre7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b9ee02656398fc8accfd2aa7ceb4aec0432f24a9d228e2d95a0f398d041b56bb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-1597 fixed by backporting the upstream fix onto the 9.4.1212.jre7 baseline. Fixed upstream in: 42.4.4 (also 42.2.28 / 42.3.9 / 42.5.5 / 42.6.1 / 42.7.2) — every one of them a Java 8 release, which is why this baseline's consumers cannot take it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-7254",
      "aliases" : [ "GHSA-735f-pc8j-v9w8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.protobuf/protobuf-java@2.4.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.protobuf/protobuf-java@2.4.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b656801e90f840d61e9989e316eaeda90c373af0d93537e2133da04e0531854b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 2.4.1 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 2.x line was never patched — no fix exists on the baseline series."
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-7254",
      "aliases" : [ "GHSA-735f-pc8j-v9w8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.protobuf/protobuf-java@2.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.protobuf/protobuf-java@2.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "67bc1073cab4f5462d95207490490dce9e73bc00a3b2cd5a01e78587a75a0753"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 2.5.0 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 2.x line was never patched — no fix exists on the baseline series."
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-7254",
      "aliases" : [ "GHSA-735f-pc8j-v9w8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.protobuf/protobuf-java@2.6.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.protobuf/protobuf-java@2.6.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4b491a337de3cb7f637ddf2d88bc40f2b1b65181a30f8b703210e60641cad6f1"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 2.6.1 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 2.x line was never patched — no fix exists on the baseline series."
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-7254",
      "aliases" : [ "GHSA-735f-pc8j-v9w8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 3.19.6 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 3.19.x line was never patched — no fix exists on the baseline series."
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-7254",
      "aliases" : [ "GHSA-735f-pc8j-v9w8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/com.google.protobuf/protobuf-java@3.19.6%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "d4c9af9b15c1135bdaf6dfbbb6cbe13d225578076e0847cf7440170f00c29211"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-7254 fixed by backporting the upstream fix onto the 3.19.6 baseline. Fixed upstream in: 3.25.5 (also 4.27.5 / 4.28.2). The 3.19.x line was never patched — no fix exists on the baseline series."
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-13990",
      "aliases" : [ "GHSA-9qcf-c26r-x5rf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.quartz-scheduler/quartz@2.3.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.quartz-scheduler/quartz@2.3.1%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-13990 fixed by backporting the upstream fix onto the 2.3.1 baseline. Fixed upstream in: 2.3.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-34062",
      "aliases" : [ "GHSA-xjhv-p3fv-x24r" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.projectreactor.netty/reactor-netty-core@1.0.19%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.projectreactor.netty/reactor-netty-core@1.0.19%2Bbackpatch.001"
      }
    }, {
      "@id" : "pkg:maven/io.projectreactor.netty/reactor-netty-http@1.0.19%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.projectreactor.netty/reactor-netty-http@1.0.19%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-34062 fixed by backporting the upstream fix onto the 1.0.19 baseline. Fixed upstream in: 1.0.39 and 1.1.13 (NVD). NOTE: the analyst hint's '1.0.24 / 1.1.0' is INCORRECT — verified against NVD and the actual fix commit, which is an ancestor of v1.0.39 (not v1.0.24)."
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-1471",
      "aliases" : [ "GHSA-mjmj-j48q-9wg2" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.yaml/snakeyaml@1.33%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.yaml/snakeyaml@1.33%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "998cd3acb23ae45baf91b67f5bc059cd23a84adad5399d409f9a0c58f8b5db2c"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-1471 fixed by backporting the upstream fix onto the 1.33 baseline. Fixed upstream in: 2.0 (secure-by-default via TagInspector; no fix on the 1.x line)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22022",
      "aliases" : [ "BIT-solr-2026-22022", "GHSA-qr3p-2xj2-q7hq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.solr/solr-core@8.11.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.solr/solr-core@8.11.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "cd2a01ed2f9af26a337076702235ec35c6c242ffcd02a62a8b8e2da233eee3b3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22022 fixed by backporting the upstream fix onto the 8.11.4 baseline. Fixed upstream in: 9.10.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-22946",
      "aliases" : [ "BIT-spark-2023-22946", "GHSA-329j-jfvr-rhr6", "PYSEC-2023-44" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4f6882bc0588ebf66d404bfe5ae339f8525ac33f7b5feadeb491bdadd992fa05"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-22946 fixed by backporting the upstream fix onto the 2.4.8 baseline. Fixed upstream in: 3.4.0 — no 2.4.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-54920",
      "aliases" : [ "BIT-spark-2025-54920", "GHSA-jwp6-cvj8-fw65" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.spark/spark-core_2.11@2.4.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4f6882bc0588ebf66d404bfe5ae339f8525ac33f7b5feadeb491bdadd992fa05"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-54920 fixed by backporting the upstream fix onto the 2.4.8 baseline. Fixed upstream in: 3.5.7 — no 2.4.x line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-22946",
      "aliases" : [ "BIT-spark-2023-22946", "GHSA-329j-jfvr-rhr6", "PYSEC-2023-44" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b5406a0fe865a2f5b13541805657de0036b9f84ffeeccd32cf85d28ef870662d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-22946 fixed by backporting the upstream fix onto the 3.0.3 baseline. Fixed upstream in: 3.4.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-54920",
      "aliases" : [ "BIT-spark-2025-54920", "GHSA-jwp6-cvj8-fw65" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.spark/spark-core_2.12@3.0.3%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b5406a0fe865a2f5b13541805657de0036b9f84ffeeccd32cf85d28ef870662d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-54920 fixed by backporting the upstream fix onto the 3.0.3 baseline. Fixed upstream in: 3.5.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-27772",
      "aliases" : [ "GHSA-cm59-pr5q-cw85" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4a73eef8b4f5df6eefb1036558b7ca44127b6169801dec8dab8b8298c0d9c411"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bdcf5c16ee1ea378ae564c8b0d8552755628f41d0bcc97aa901861d0cd5c1abf"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-27772 fixed by backporting the upstream fix onto the 1.5.22.RELEASE baseline. Fixed upstream in: 2.2.11.RELEASE — the 1.5 line was EOL a year before the fix landed (667ccdae84, 2020-10-13)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-20883",
      "aliases" : [ "GHSA-xf96-w227-r7c4" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot@1.5.22.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4a73eef8b4f5df6eefb1036558b7ca44127b6169801dec8dab8b8298c0d9c411"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-autoconfigure@1.5.22.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bdcf5c16ee1ea378ae564c8b0d8552755628f41d0bcc97aa901861d0cd5c1abf"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-20883 fixed by backporting the upstream fix onto the 1.5.22.RELEASE baseline. Fixed upstream in: 2.5.15 / 2.6.15 / 2.7.12 / 3.0.7 — the CVE record names 2.5.14 and earlier as affected, which includes this baseline"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22733",
      "aliases" : [ "GHSA-mgvc-8q2h-5pgc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.002"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22733 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.12 / 4.0.4 (OSS); 2.7.32 / 3.3.18 / 3.4.15 are commercial-only (Tanzu), not on Maven Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22733",
      "aliases" : [ "GHSA-mgvc-8q2h-5pgc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.003",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator@2.7.18%2Bbackpatch.003"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.003",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-actuator-autoconfigure@2.7.18%2Bbackpatch.003"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22733 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.12 / 4.0.4 (OSS); 2.7.32 / 3.3.18 / 3.4.15 are commercial-only (Tanzu), not on Maven Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40972",
      "aliases" : [ "GHSA-56v8-86gj-66jp" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.boot/spring-boot-devtools@2.7.18%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.boot/spring-boot-devtools@2.7.18%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "19887caaf4ba20d852f15685089fd4339d409532c18be911734f39cd0278a1e4"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40972 fixed by backporting the upstream fix onto the 2.7.18 baseline. Fixed upstream in: 3.5.14 / 4.0.6 (OSS); 2.7.33 / 3.3.19 / 3.4.16 are commercial-only (Tanzu), not on Maven Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40982",
      "aliases" : [ "GHSA-6g23-24mc-hx6x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2ead94c6b153e55748c1b0dd1094fd2ccdc1d3e0902ba2a797b2f6d7c29faef2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 3.1.10 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 3.1.x affected from 3.1.0 through 3.1.13, fixed only in 3.1.14 (Enterprise Support Only)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22739",
      "aliases" : [ "GHSA-3qwq-q9vm-5j42" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2ead94c6b153e55748c1b0dd1094fd2ccdc1d3e0902ba2a797b2f6d7c29faef2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 3.1.10 baseline. Fixed upstream in: 4.3.2 / 5.0.2 — CNA records 3.1.x affected before 3.1.13"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41002",
      "aliases" : [ "GHSA-86wq-234q-r6wg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@3.1.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2ead94c6b153e55748c1b0dd1094fd2ccdc1d3e0902ba2a797b2f6d7c29faef2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 3.1.10 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 3.1.x affected from 3.1.0 through 3.1.13"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40982",
      "aliases" : [ "GHSA-6g23-24mc-hx6x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ce9402a609d06bc0d712f4f7d5ef2b78261eb975636ee149e1d0396142570893"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.1.0 through 4.1.10 affected; 4.1.10 is Enterprise Support Only"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22739",
      "aliases" : [ "GHSA-3qwq-q9vm-5j42" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ce9402a609d06bc0d712f4f7d5ef2b78261eb975636ee149e1d0396142570893"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.2 / 5.0.2 — CNA records 4.1.x affected before 4.1.9"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40981",
      "aliases" : [ "GHSA-2mh5-3cw6-hrrq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ce9402a609d06bc0d712f4f7d5ef2b78261eb975636ee149e1d0396142570893"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40981 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.1.0 through 4.1.10 affected"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41002",
      "aliases" : [ "GHSA-86wq-234q-r6wg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.1.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ce9402a609d06bc0d712f4f7d5ef2b78261eb975636ee149e1d0396142570893"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 4.1.7 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.1.0 through 4.1.10 affected"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40982",
      "aliases" : [ "GHSA-6g23-24mc-hx6x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "93e7865374bc93554ccf2b7996d5b58ce776f7f9d2ff03889e3c6bab7f206563"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 (breaking Spring Boot 3.5 / dependency-train jump for the 4.2.x line)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22739"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "93e7865374bc93554ccf2b7996d5b58ce776f7f9d2ff03889e3c6bab7f206563"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41002",
      "aliases" : [ "GHSA-86wq-234q-r6wg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "93e7865374bc93554ccf2b7996d5b58ce776f7f9d2ff03889e3c6bab7f206563"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.2.0 through 4.2.7 affected"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40982",
      "aliases" : [ "GHSA-6g23-24mc-hx6x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8e0692691ed63b559865625500c0e943d1513b71e8a532b0fa87a45b9a786a98"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40982 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 (breaking Spring Boot 3.5 / dependency-train jump for the 4.2.x line)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22739",
      "aliases" : [ "GHSA-3qwq-q9vm-5j42" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8e0692691ed63b559865625500c0e943d1513b71e8a532b0fa87a45b9a786a98"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22739 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41002",
      "aliases" : [ "GHSA-86wq-234q-r6wg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8e0692691ed63b559865625500c0e943d1513b71e8a532b0fa87a45b9a786a98"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41002 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.2.0 through 4.2.7 affected"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40981",
      "aliases" : [ "GHSA-2mh5-3cw6-hrrq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-config-server@4.2.4%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8e0692691ed63b559865625500c0e943d1513b71e8a532b0fa87a45b9a786a98"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40981 fixed by backporting the upstream fix onto the 4.2.4 baseline. Fixed upstream in: 4.3.3 / 5.0.3 — CNA records 4.2.0 through 4.2.7 affected"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22963",
      "aliases" : [ "GHSA-6v73-fgf6-w5j7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-function-context@3.1.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-function-context@3.1.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6e977ff223351b4ad6ea77ee72973adf7f41a4e68a34a9f1768b542933b5e2d2"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-function-core@3.1.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-function-core@3.1.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6e1c07748e0aa49e9c14448a56627ccfa61feaa11f22077993cdf5b6a405b353"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22963 fixed by backporting the upstream fix onto the 3.1.6 baseline. Fixed upstream in: 3.1.7 and 3.2.3 (same org.springframework.cloud coordinate; 3.1.x line got the fix in 3.1.7, but consumers pinned to 3.1.6 have no in-place same-version fix)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22947",
      "aliases" : [ "GHSA-3gx9-37ww-9qw6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e5d056a71dda491eb47b892fa3690f83a665f021fcbb76a87e54aa1fdb758caa"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22947 fixed by backporting the upstream fix onto the 2.2.10.RELEASE baseline. Fixed upstream in: 3.0.7 and 3.1.1 — never on the 2.2.x line, which was already EOL"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-41235",
      "aliases" : [ "GHSA-6j2q-c73v-97c5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@2.2.10.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e5d056a71dda491eb47b892fa3690f83a665f021fcbb76a87e54aa1fdb758caa"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-41235 fixed by backporting the upstream fix onto the 2.2.10.RELEASE baseline. Fixed upstream in: 3.1.10 / 4.0.12 / 4.1.8 / 4.2.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22947",
      "aliases" : [ "GHSA-3gx9-37ww-9qw6" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@3.0.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.cloud/spring-cloud-gateway-server@3.0.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "66be0dd65e14fe8aa21cf46efb0e2a6b09d019e9bd1df9e462b801c5e5fa1063"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22947 fixed by backporting the upstream fix onto the 3.0.6 baseline. Fixed upstream in: 3.0.7 and 3.1.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22980",
      "aliases" : [ "GHSA-w24x-87mr-4r23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.1.15%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.1.15%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6a2bf42ca99a83afad14f4f94ab05c62f7889dedbed1b38987ec2689c2d7c508"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22980 fixed by backporting the upstream fix onto the 3.1.15 baseline. Fixed upstream in: 3.3.5 and 3.4.1 (same coordinate; the 3.1.x line ended at 3.1.15 and never got the fix)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22980",
      "aliases" : [ "GHSA-w24x-87mr-4r23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.2.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.data/spring-data-mongodb@3.2.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "27775914ff4b1d3ad8440341b687d79359140fec04a9f52808236c63b82078ad"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22980 fixed by backporting the upstream fix onto the 3.2.12 baseline. Fixed upstream in: 3.3.5 and 3.4.1 (same coordinate; the 3.2.x line ended at 3.2.12 and never got the fix)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22243",
      "aliases" : [ "GHSA-ccgv-vj62-xf9h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22259",
      "aliases" : [ "GHSA-hgjh-9rj2-g67j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22262",
      "aliases" : [ "GHSA-2wrp-6fg6-hmc5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22243",
      "aliases" : [ "GHSA-ccgv-vj62-xf9h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22259",
      "aliases" : [ "GHSA-hgjh-9rj2-g67j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22262",
      "aliases" : [ "GHSA-2wrp-6fg6-hmc5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@4.3.30.RELEASE%2Bbackpatch.002"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 4.3.30.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22243",
      "aliases" : [ "GHSA-ccgv-vj62-xf9h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5617fd140565d2967eb89b11c471d44fec2f6daf60fb3b24655f6aae0c62e4c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.0.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22259",
      "aliases" : [ "GHSA-hgjh-9rj2-g67j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5617fd140565d2967eb89b11c471d44fec2f6daf60fb3b24655f6aae0c62e4c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.0.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22262",
      "aliases" : [ "GHSA-2wrp-6fg6-hmc5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.0.20.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5617fd140565d2967eb89b11c471d44fec2f6daf60fb3b24655f6aae0c62e4c2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.0.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22243",
      "aliases" : [ "GHSA-ccgv-vj62-xf9h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1afddafbe67eaf6d96dc57805871aec825b8fd571812bc4ae720f63372e61a27"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22259",
      "aliases" : [ "GHSA-hgjh-9rj2-g67j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1afddafbe67eaf6d96dc57805871aec825b8fd571812bc4ae720f63372e61a27"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22262",
      "aliases" : [ "GHSA-2wrp-6fg6-hmc5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1afddafbe67eaf6d96dc57805871aec825b8fd571812bc4ae720f63372e61a27"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22243",
      "aliases" : [ "GHSA-ccgv-vj62-xf9h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8f79ac78087098d1392080021d8720d6edaecfda452e0b1cbf0bcb95df0762e3"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "63d066a516e43f29c6e74ef8abfde6511c71a9241a2140e9af9602dcf4fcabd5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22259",
      "aliases" : [ "GHSA-hgjh-9rj2-g67j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8f79ac78087098d1392080021d8720d6edaecfda452e0b1cbf0bcb95df0762e3"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "63d066a516e43f29c6e74ef8abfde6511c71a9241a2140e9af9602dcf4fcabd5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22262",
      "aliases" : [ "GHSA-2wrp-6fg6-hmc5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8f79ac78087098d1392080021d8720d6edaecfda452e0b1cbf0bcb95df0762e3"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "63d066a516e43f29c6e74ef8abfde6511c71a9241a2140e9af9602dcf4fcabd5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — the 4.3 line was EOL from 2020-12-31 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22965",
      "aliases" : [ "GHSA-36p3-wjmg-h94x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8f79ac78087098d1392080021d8720d6edaecfda452e0b1cbf0bcb95df0762e3"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "63d066a516e43f29c6e74ef8abfde6511c71a9241a2140e9af9602dcf4fcabd5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22965 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 5.2.20.RELEASE / 5.3.18 — both later GENERATIONS, so the 5.1 line never received it and 5.1.20.RELEASE is terminal on Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41845"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8f79ac78087098d1392080021d8720d6edaecfda452e0b1cbf0bcb95df0762e3"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-beans@5.1.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "63d066a516e43f29c6e74ef8abfde6511c71a9241a2140e9af9602dcf4fcabd5"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 5.1.20.RELEASE baseline. Fixed upstream in: 6.2.19 / 7.0.8 — the CNA's oldest enumerated range is 5.3.0-5.3.48 and does not name the 5.1 line; the defect is present here regardless, measured against the released jar (see notes)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22243",
      "aliases" : [ "GHSA-ccgv-vj62-xf9h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8e23835666c1ff8a0a15b7db7b8dc4de803d9dea1eff521c213cb7be930e3d48"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22243 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 5.3.32 / 6.0.17 / 6.1.4 — OSS 5.2 ended at 5.2.25.RELEASE on 2023-07-13 and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22259",
      "aliases" : [ "GHSA-hgjh-9rj2-g67j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8e23835666c1ff8a0a15b7db7b8dc4de803d9dea1eff521c213cb7be930e3d48"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22259 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 5.3.33 / 6.0.18 / 6.1.5 — OSS 5.2 ended at 5.2.25.RELEASE and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22262",
      "aliases" : [ "GHSA-2wrp-6fg6-hmc5" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8e23835666c1ff8a0a15b7db7b8dc4de803d9dea1eff521c213cb7be930e3d48"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22262 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 5.3.34 / 6.0.19 / 6.1.6 — OSS 5.2 ended at 5.2.25.RELEASE and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41845"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.2.25.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8e23835666c1ff8a0a15b7db7b8dc4de803d9dea1eff521c213cb7be930e3d48"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 5.2.25.RELEASE baseline. Fixed upstream in: 6.2.19 / 7.0.8 — the CNA's oldest enumerated range is 5.3.0-5.3.48 and does not name the 5.2 line; the defect is present here regardless, measured against the released jar (see notes)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-38816",
      "aliases" : [ "GHSA-cx7f-g6mp-7hqm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-core@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-core@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-beans@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-beans@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-context@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-context@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-web@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-webmvc@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-webmvc@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-webflux@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-webflux@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-expression@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-expression@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-aop@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-aop@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-tx@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-tx@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-jdbc@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-jdbc@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-orm@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-orm@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-messaging@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-messaging@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-test@5.3.39%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-test@5.3.39%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-38816 fixed by backporting the upstream fix onto the 5.3.39 baseline. Fixed upstream in: 6.1.13 (commercial-support backport may exist via Broadcom/VMware Spring Enterprise Support)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41845"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "46f8b0ece6830d8f8fd08efbcea5f175d23cf62b608db09d3266c69877ce1dae"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41845"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "bae8066cad405e05c82112f5ad0f7ab0a197a29ac8d512dcec0c49a470455815"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "867be95c54ebfc5c7584dcf4a06385b866e880668c08c50685474d05b89b261e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41845 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41848",
      "aliases" : [ "GHSA-659m-px2c-25wj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-web@6.1.21%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "bae8066cad405e05c82112f5ad0f7ab0a197a29ac8d512dcec0c49a470455815"
      }
    }, {
      "@id" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework/spring-core@6.1.21%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "867be95c54ebfc5c7584dcf4a06385b866e880668c08c50685474d05b89b261e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41848 fixed by backporting the upstream fix onto the 6.1.21 baseline. Fixed upstream in: 6.2.19 / 7.0.8 (and, per the CNA, the commercial-only 6.1.28)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41007",
      "aliases" : [ "GHSA-439x-6767-44cv" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "586098c8593c3eb903183d54cec857fce20662641715032af52f1bd9392da56a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41007 fixed by backporting the upstream fix onto the 1.5.6 baseline. Fixed upstream in: 2.5.3 / 3.0.4 / 3.1 (no 1.5.x line fix — 1.5.x is EOL, terminal at 1.5.6)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41006",
      "aliases" : [ "GHSA-7fxc-486f-32q9" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.hateoas/spring-hateoas@1.5.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "586098c8593c3eb903183d54cec857fce20662641715032af52f1bd9392da56a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41006 fixed by backporting the upstream fix onto the 1.5.6 baseline. Fixed upstream in: 2.5.3 / 3.0.4 (no 1.5.x line fix — 1.5.x is EOL, terminal at 1.5.6)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2018-1263",
      "aliases" : [ "GHSA-87vg-5pgx-pggh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.integration/spring-integration-zip@1.0.0.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.integration/spring-integration-zip@1.0.0.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2018-1263 fixed by backporting the upstream fix onto the 1.0.0.RELEASE baseline. Fixed upstream in: 1.0.2.RELEASE (a partial, '..'-gated fix shipped in 1.0.1.RELEASE; NVD marks the CVE fixed in 1.0.2)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-34040",
      "aliases" : [ "GHSA-crqf-q9fp-hwjw" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.kafka/spring-kafka@2.8.11%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.kafka/spring-kafka@2.8.11%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-34040 fixed by backporting the upstream fix onto the 2.8.11 baseline. Fixed upstream in: 2.9.11 and 3.0.10 — the 2.8.x line was EOL and never patched, so the pinned 2.8.x coordinate has no same-line fix"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41720",
      "aliases" : [ "GHSA-jrv5-8w28-4265" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.ldap/spring-ldap-core@2.4.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.ldap/spring-ldap-core@2.4.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8ff4db455dbf4e298dec6ca1bb0eb926d00180d0bb87d60250c26964352c4121"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41720 fixed by backporting the upstream fix onto the 2.4.4 baseline. Fixed upstream in: 3.3.8 / 4.0.4 OSS (breaking line/major jump for 2.4.x and 3.2.x consumers); 2.4.5 / 3.2.17 are Enterprise-only, never on Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22978",
      "aliases" : [ "GHSA-hh32-7344-cg2f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22978 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.4.11 / 5.5.7 / 5.6.4 / 5.7.0 / 5.8.0 / 6.0.0 — the 4.2 line was EOL before the embargo and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-22112",
      "aliases" : [ "GHSA-gq28-h5vg-8prx" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-22112 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.2.9.RELEASE / 5.3.8.RELEASE / 5.4.4 / 5.5.0 — landed 2021-01-28, after 4.2.20.RELEASE was cut (2020-12-09) and after the 4.2 line was EOL"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22257"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.001"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22257 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.12 / 5.8.11 / 6.1.8 — the 4.2 line was a decade EOL"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-22978",
      "aliases" : [ "GHSA-hh32-7344-cg2f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "a804eb18efea484c62e5bde7dfc1bfdec94bb6ea50d73144c4fe2a9b70f9a6c5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8c224440287b5010566237536d09099a2204fa651b6531648cdbb9c58c7a8582"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-22978 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.4.11 / 5.5.7 / 5.6.4 / 5.7.0 / 5.8.0 / 6.0.0 — the 4.2 line was EOL before the embargo and never received it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-22112",
      "aliases" : [ "GHSA-gq28-h5vg-8prx" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "a804eb18efea484c62e5bde7dfc1bfdec94bb6ea50d73144c4fe2a9b70f9a6c5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8c224440287b5010566237536d09099a2204fa651b6531648cdbb9c58c7a8582"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-22112 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.2.9.RELEASE / 5.3.8.RELEASE / 5.4.4 / 5.5.0 — landed 2021-01-28, after 4.2.20.RELEASE was cut (2020-12-09) and after the 4.2 line was EOL"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-22257",
      "aliases" : [ "GHSA-f3jh-qvm4-mg39" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "a804eb18efea484c62e5bde7dfc1bfdec94bb6ea50d73144c4fe2a9b70f9a6c5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8c224440287b5010566237536d09099a2204fa651b6531648cdbb9c58c7a8582"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-22257 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.12 / 5.8.11 / 6.1.8 — the 4.2 line was a decade EOL"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "a804eb18efea484c62e5bde7dfc1bfdec94bb6ea50d73144c4fe2a9b70f9a6c5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8c224440287b5010566237536d09099a2204fa651b6531648cdbb9c58c7a8582"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.22 / 5.8.24 / 6.3.15 / 6.4.15 / 6.5.9 / 7.0.4 — 4.2 is additionally worse off, because the shouldWriteHeadersEagerly opt-out that lets later versions avoid the lazy path only arrived in 5.7"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-38827",
      "aliases" : [ "GHSA-q3v6-hm2v-pw99" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "a804eb18efea484c62e5bde7dfc1bfdec94bb6ea50d73144c4fe2a9b70f9a6c5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@4.2.20.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8c224440287b5010566237536d09099a2204fa651b6531648cdbb9c58c7a8582"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-38827 fixed by backporting the upstream fix onto the 4.2.20.RELEASE baseline. Fixed upstream in: 5.7.14 / 5.8.16 / 6.0.14 / 6.1.12 / 6.2.8 / 6.3.5 — the 4.2 line was a decade EOL"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-4977",
      "aliases" : [ "GHSA-7q9c-h23x-65fq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7d490ca4d00823d796710486466fb4e19256b63ec71cf5b44ef90962fa71464b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-4977 fixed by backporting the upstream fix onto the 2.0.9.RELEASE baseline. Fixed upstream in: 2.0.10.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2018-1260",
      "aliases" : [ "GHSA-rrpm-pj7p-7j9q" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7d490ca4d00823d796710486466fb4e19256b63ec71cf5b44ef90962fa71464b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2018-1260 fixed by backporting the upstream fix onto the 2.0.9.RELEASE baseline. Fixed upstream in: 2.0.15.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2019-3778",
      "aliases" : [ "GHSA-77rv-6vfw-x4gc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security.oauth/spring-security-oauth2@2.0.9.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7d490ca4d00823d796710486466fb4e19256b63ec71cf5b44ef90962fa71464b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2019-3778 fixed by backporting the upstream fix onto the 2.0.9.RELEASE baseline. Fixed upstream in: 2.0.17.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-31690",
      "aliases" : [ "GHSA-32vj-v39g-jh23" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-oauth2-client@5.5.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-oauth2-client@5.5.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "b51cb601877a1836950b1283e065cfc70b2abd1c0bb848f95cf6dcafbaccf97f"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-oauth2-core@5.5.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-oauth2-core@5.5.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d70227708e65e31fb2d53b69d8dd22a7eee0ac773c965905fe83e101eaaf8880"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.5.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.5.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "fb651a1b00914e1c6a3c191bfd4f39c961c2011b673e7e10cf66146b4a16536c"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.5.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.5.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "2d99d0b2260b936bca2401ec55e174f122d29b6fd7a5a22407e7c1869086eaaf"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.5.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.5.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bafa2cac838b23ac85461b76651c4c3309146c8f34229a16842a133717ece6a9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-31690 fixed by backporting the upstream fix onto the 5.5.8 baseline. Fixed upstream in: 5.6.9 / 5.7.5 — the 5.5 line was EOL before the fix and never received a release carrying it"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-22228",
      "aliases" : [ "GHSA-mg83-c7gq-rv5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4287403b8e95dab826cf68720456b0c2268d2c31079678815515c2fdf28df55b"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ea161e56b1edd250bfb84fe405b2c0447c350c78214f6aabf645cf96eaa663bd"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d985ebeb4863b74cfe8bbcad172622268448e290225b5d8e71548a884f543e38"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "462a6bc8f4ad2560f915ca510b71adf06a06c9ab46f8b63d179e5138a660e398"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4287403b8e95dab826cf68720456b0c2268d2c31079678815515c2fdf28df55b"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ea161e56b1edd250bfb84fe405b2c0447c350c78214f6aabf645cf96eaa663bd"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d985ebeb4863b74cfe8bbcad172622268448e290225b5d8e71548a884f543e38"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.6.12%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "462a6bc8f4ad2560f915ca510b71adf06a06c9ab46f8b63d179e5138a660e398"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.6.12 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-22228",
      "aliases" : [ "GHSA-mg83-c7gq-rv5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ea138cad4039007e3de288d885d20cd9673ffad14e8f187429f2bfd15cb2b6c6"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7981b9a2d806398c364ee489a46166df87bfde6bbd50f6097a453816553bed03"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bd5914aa9053a501c0e2bb9c7279de63f8a5535e9868be3d37e5323ba161fc85"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9cb925dbf0b5b2ba62752bec41074d4c7d3c5497c40df169560b378bfb59a387"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ea138cad4039007e3de288d885d20cd9673ffad14e8f187429f2bfd15cb2b6c6"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7981b9a2d806398c364ee489a46166df87bfde6bbd50f6097a453816553bed03"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "bd5914aa9053a501c0e2bb9c7279de63f8a5535e9868be3d37e5323ba161fc85"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.8.16%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9cb925dbf0b5b2ba62752bec41074d4c7d3c5497c40df169560b378bfb59a387"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.8.16 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "null"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "f030d34bd278b0ffe9fd3d72851420f7a16ff3c7c1e1a5e28a06339409ccbc06"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "0eb15300e75e08bc10eb83fdafcbbc619cb0d9fc8e5a1c4593ada7343ce31fd5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "dd5ed4416c28f8a51a87875a08e132a6854af20d1b68316fa42a56072a27093c"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "3c0282b4f62d0bf033de4f0d5c0426813788284b2e1f34ddabc250cf4017bbdf"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS (breaking jakarta 6.x/7.x); 5.7.22 / 5.8.24 are Broadcom Enterprise-support-only, never published to Central"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-22228"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "f030d34bd278b0ffe9fd3d72851420f7a16ff3c7c1e1a5e28a06339409ccbc06"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "0eb15300e75e08bc10eb83fdafcbbc619cb0d9fc8e5a1c4593ada7343ce31fd5"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "dd5ed4416c28f8a51a87875a08e132a6854af20d1b68316fa42a56072a27093c"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@5.7.14%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "3c0282b4f62d0bf033de4f0d5c0426813788284b2e1f34ddabc250cf4017bbdf"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 5.7.14 baseline. Fixed upstream in: 5.7.16 / 5.8.18 / 6.0.16 / 6.1.14 / 6.2.10 / 6.3.8 / 6.4.4 — of these only the 6.x releases reached Central; 5.7.16 is Broadcom Enterprise-support-only"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8734c87268db3fde4d331413b63fb3ae5f3fa61216206448708aee0025cd0adb"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f878e7330157b3fbf1ed160a679582e617a37c0eeddfbb40ae482fb6d67e5331"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "891b279f1482c17342f0150f67bc9ca31c49f8ea52fd8263eff210298c398322"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "94015d361b0a3bcc713cd8cc0230f69a8392666f8db244542eddd356f996bdd8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-22228",
      "aliases" : [ "GHSA-mg83-c7gq-rv5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8734c87268db3fde4d331413b63fb3ae5f3fa61216206448708aee0025cd0adb"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f878e7330157b3fbf1ed160a679582e617a37c0eeddfbb40ae482fb6d67e5331"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "891b279f1482c17342f0150f67bc9ca31c49f8ea52fd8263eff210298c398322"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "94015d361b0a3bcc713cd8cc0230f69a8392666f8db244542eddd356f996bdd8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.0.8 baseline. Fixed upstream in: 6.0.16 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "59fa2916deec91e47585b5b82ce1a552cae0bc673bcfc9c18097980c9399c4af"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f9ab84b435366db6da624f2d0e0507108d7746dcad6bddd37342c8846885ddef"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d7e1ded3a9c0c6c509ea9cabf8cbced1e1921c377d7da44ea2887d04a2e40e28"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1a23c50d1a9067e3437d533da1c00f803f6c8d787cdc267e8e3c491961a06915"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-22228",
      "aliases" : [ "GHSA-mg83-c7gq-rv5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "59fa2916deec91e47585b5b82ce1a552cae0bc673bcfc9c18097980c9399c4af"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f9ab84b435366db6da624f2d0e0507108d7746dcad6bddd37342c8846885ddef"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d7e1ded3a9c0c6c509ea9cabf8cbced1e1921c377d7da44ea2887d04a2e40e28"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.1.9%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1a23c50d1a9067e3437d533da1c00f803f6c8d787cdc267e8e3c491961a06915"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.1.9 baseline. Fixed upstream in: 6.1.14 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5ff46a66cdece44f1500d98b174ee1e8d5cf6a83c510c9e0ec9d5301cee56c4f"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6e047f3a4cef94d96ef0d55dc4bec5cdf04d3f7ea8e37e868d9ad0b91f4ee00e"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "327714680e035de0c141b54c441eb0414abec5bd76901a3055f52cc2de5b6df1"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9de8eeb200305f91241b076221b09a804ef5a00ec13801e9bb99ede1aaf345d9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-22228",
      "aliases" : [ "GHSA-mg83-c7gq-rv5c" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "5ff46a66cdece44f1500d98b174ee1e8d5cf6a83c510c9e0ec9d5301cee56c4f"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6e047f3a4cef94d96ef0d55dc4bec5cdf04d3f7ea8e37e868d9ad0b91f4ee00e"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "327714680e035de0c141b54c441eb0414abec5bd76901a3055f52cc2de5b6df1"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.2.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "9de8eeb200305f91241b076221b09a804ef5a00ec13801e9bb99ede1aaf345d9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-22228 fixed by backporting the upstream fix onto the 6.2.8 baseline. Fixed upstream in: 6.2.10 — PROBED 2026-08-27: 404 on Central, it was never released. The 6.3 and 6.4 fixes (6.3.8, 6.4.4) DID reach Central, which is why those two baselines are already fixed and carry no BCrypt patch here."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "705a8f91d8222f6ff0ed7a0bb2ccba605a240434f4c12836f61e589100d5a7c8"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "02dbfdcaff3e5ccf33058b40f6d07a9a932de1287684fb74a3882bbf50c08477"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ab457e8c7986d7fea97704c18019880c7326fd25b6ba47c815475dcf8f19edcc"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e781d196c027ce206a5c7fe354f369c66aabc11d11feda9c0d6adfa5a32a377c"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.3.10 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-22732",
      "aliases" : [ "GHSA-mf92-479x-3373" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.security/spring-security-web@6.4.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-web@6.4.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "3a591ecdc512df02e1c5ffc1680dcae883392f0887a15391e3849fdf0c9d0504"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-config@6.4.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-config@6.4.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "97c5d3d7cc12d2eb0688932e21ef7fe55a71d7d70151b81b6fd5174d5902c44b"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-core@6.4.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-core@6.4.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "04912edbd2d384bddd9ac4435b0fc292a4e6b901283a9f2a6b10128676da6675"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.security/spring-security-crypto@6.4.13%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.security/spring-security-crypto@6.4.13%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4913e942527d4573a4be69467f65ead3a633631d68bf35db077e12da39d28794"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-22732 fixed by backporting the upstream fix onto the 6.4.13 baseline. Fixed upstream in: 6.5.9 / 7.0.4 OSS. The 6.2 line stops at 6.2.8 on Central and never received it; taking 6.5.x means moving from Spring Boot 3.2 to 3.5."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40998",
      "aliases" : [ "GHSA-2mpf-m756-hxjm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.springframework.ws/spring-xml@4.0.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.ws/spring-xml@4.0.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7d554bfdb00523ae2841845376c2d60b36ac251fb32c2a420c087b3db3b94dee"
      }
    }, {
      "@id" : "pkg:maven/org.springframework.ws/spring-ws-core@4.0.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.springframework.ws/spring-ws-core@4.0.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "95cca428336771b058e2bd4a217d01b08d420d30bd012aafd1e530720d8256fb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40998 fixed by backporting the upstream fix onto the 4.0.17 baseline. Fixed upstream in: 4.1.4 / 5.0.2 OSS; 3.1.9 / 4.0.19 are Enterprise-support-only (never on Central)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-45047",
      "aliases" : [ "GHSA-fhw8-8j55-vwgq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.sshd/sshd-core@2.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "79678edf69ae42e10dd27be98c495825658b381769e66712ca29550375b32440"
      }
    }, {
      "@id" : "pkg:maven/org.apache.sshd/sshd-common@2.5.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.5.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "50576494aceddbd4ccb306d7ab3a35f332e3a08dabe629e8c9cfdbf53b0a70ae"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.5.1 baseline. Fixed upstream in: 2.9.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-45047",
      "aliases" : [ "GHSA-fhw8-8j55-vwgq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.sshd/sshd-core@2.6.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.6.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8c01236eab15bdaea1f004a50d8dc3e0fe1d567ac386cf19babf66f27c4ee3ec"
      }
    }, {
      "@id" : "pkg:maven/org.apache.sshd/sshd-common@2.6.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.6.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "1abd2a036477575cb883be5f269b1a65136240f892de2b15925866b8dcda2b47"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 2.9.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-45047",
      "aliases" : [ "GHSA-fhw8-8j55-vwgq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.sshd/sshd-core@2.7.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.7.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6d18b3e2ad33778f932e46b4bf098d1781b79eea9b52aa42de53f3bbbd6b9693"
      }
    }, {
      "@id" : "pkg:maven/org.apache.sshd/sshd-common@2.7.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.7.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ff3cacc339bef5cd888e40b7d76315b0f3d1a0d228e5ae2d591e721c9591f7dd"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.7.0 baseline. Fixed upstream in: 2.9.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-45047",
      "aliases" : [ "GHSA-fhw8-8j55-vwgq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.sshd/sshd-core@2.8.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.8.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "a76f79cd60a0bed1b290d648abd0038bac0628f36c9af7653f78f7b72e7b2841"
      }
    }, {
      "@id" : "pkg:maven/org.apache.sshd/sshd-common@2.8.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.8.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8c756497d0fe6352de8d09c4d79c6e026ed1ec3b70d2a0892cd9497c02dc87ab"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.8.0 baseline. Fixed upstream in: 2.9.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-45047",
      "aliases" : [ "GHSA-fhw8-8j55-vwgq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.sshd/sshd-core@2.9.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-core@2.9.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "25ad7fb930d5711b121a67dd434d620517e5675c82523c03be8cdd31a78a527c"
      }
    }, {
      "@id" : "pkg:maven/org.apache.sshd/sshd-common@2.9.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.sshd/sshd-common@2.9.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6372631f3f5f2d6557c1e791a7ae33dfb926f771bdefd1bc9ba2b31e7ca9ef01"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-45047 fixed by backporting the upstream fix onto the 2.9.1 baseline. Fixed upstream in: 2.9.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1181",
      "aliases" : [ "GHSA-7jw3-5q4w-89qg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f65c70fb109b33651f01cf551dcbc70fdd64c3db9e3aa982b2c32afc1097c325"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1181 fixed by a patch applied onto the 1.3.10 baseline; no upstream release carries this fix. Upstream status: none"
  }, {
    "vulnerability" : {
      "name" : "CVE-2016-1182",
      "aliases" : [ "GHSA-5ggr-mpgw-3mgx" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f65c70fb109b33651f01cf551dcbc70fdd64c3db9e3aa982b2c32afc1097c325"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2016-1182 fixed by a patch applied onto the 1.3.10 baseline; no upstream release carries this fix. Upstream status: none"
  }, {
    "vulnerability" : {
      "name" : "CVE-2015-0899",
      "aliases" : [ "GHSA-cvvx-r33m-v7pq" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts-core@1.3.10%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f65c70fb109b33651f01cf551dcbc70fdd64c3db9e3aa982b2c32afc1097c325"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2015-0899 fixed by a patch applied onto the 1.3.10 baseline; no upstream release carries this fix. Upstream status: none"
  }, {
    "vulnerability" : {
      "name" : "CVE-2024-53677",
      "aliases" : [ "GHSA-43mq-6xmg-29vm" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4fb8ac8566b7945207b45c6d80d0ae68fc3b3cadd98e45d27feca77fe23496cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2024-53677 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.4.0 (via the replacement action-based upload mechanism; NO fix was ever released for the 2.5.x line, and 2.5.33 is terminal 2.5.x)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66675",
      "aliases" : [ "GHSA-rg58-xhh7-mqjw" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4fb8ac8566b7945207b45c6d80d0ae68fc3b3cadd98e45d27feca77fe23496cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66675 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.8.0 / 7.1.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-64775",
      "aliases" : [ "GHSA-xx7v-hqxh-cjr9" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4fb8ac8566b7945207b45c6d80d0ae68fc3b3cadd98e45d27feca77fe23496cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-64775 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.8.0 / 7.1.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-68493",
      "aliases" : [ "GHSA-qcfc-hmrc-59x7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts2-core@2.5.33%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4fb8ac8566b7945207b45c6d80d0ae68fc3b3cadd98e45d27feca77fe23496cb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-68493 fixed by backporting the upstream fix onto the 2.5.33 baseline. Fixed upstream in: 6.1.1 (the fix commit is in the STRUTS_6_1_0 tag, but 6.1.0 was never released to Central — 6.1.1 is the first RELEASE carrying it)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-50164",
      "aliases" : [ "GHSA-2j39-qcjm-428w" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts/struts2-core@2.3.37%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts/struts2-core@2.3.37%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8b3b749f64ed109db2a220a756e81c1bda13dda7d75553fc509184e827db7e7b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-50164 fixed by backporting the upstream fix onto the 2.3.37 baseline. Fixed upstream in: 2.5.33 and 6.3.0.2 (no fix ever released in the 2.3.x line — 2.3.37 is terminal 2.3.x and is affected)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-17531",
      "aliases" : [ "GHSA-c566-2grg-mjwg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c0cf9cdc52c2f0ecf81f6dfbdac6f1769764e731bd652ef777b675e87aeef5a2"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-17531 fixed by a patch applied onto the 4.1.6 baseline; no upstream release carries this fix. Upstream status: none (Tapestry 4 EOL 2008; Apache declined to patch the 4.x line and the advisory says upgrade to Tapestry 5.x, a full rewrite)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-17531",
      "aliases" : [ "GHSA-c566-2grg-mjwg" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tapestry/tapestry-framework@4.1.6%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "58a60afe54de02a9f0327ce9480ee11c8a3253901b9189b02e003e0b99bcdf87"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-17531 fixed by a patch applied onto the 4.1.6 baseline; no upstream release carries this fix. Upstream status: none (Tapestry 4 EOL 2008; Apache declined to patch the 4.x line and the advisory says upgrade to Tapestry 5.x, a full rewrite)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-27850",
      "aliases" : [ "GHSA-mj8x-cpr8-x39h" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "02eab9781d2e3ee8453625a2e97390e18bfec7bd2629409668694b2d6ed590b8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-27850 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.6.3 / 5.7.1"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-30638",
      "aliases" : [ "GHSA-ghm8-mmx7-xvg2" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "02eab9781d2e3ee8453625a2e97390e18bfec7bd2629409668694b2d6ed590b8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-30638 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.6.4 / 5.7.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-13953",
      "aliases" : [ "GHSA-w9mp-p2wp-2xf7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "02eab9781d2e3ee8453625a2e97390e18bfec7bd2629409668694b2d6ed590b8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-13953 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.6.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-31781",
      "aliases" : [ "GHSA-227g-7cvv-6ff3" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tapestry/tapestry-core@5.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "02eab9781d2e3ee8453625a2e97390e18bfec7bd2629409668694b2d6ed590b8"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-31781 fixed by backporting the upstream fix onto the 5.5.0 baseline. Fixed upstream in: 5.8.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43869",
      "aliases" : [ "BIT-thrift-2026-43869", "GHSA-7pwc-h2j2-rjgj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.thrift/libthrift@0.13.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.thrift/libthrift@0.13.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "511c847fdd6504757c92372c58a9f4497312b84d358d5a0288d3d5e93a10db3d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43869 fixed by backporting the upstream fix onto the 0.13.0 baseline. Fixed upstream in: 0.23.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40478"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c466ae64359cc298b22d26a266e81224b032547d6ec06b5da0830d7baa98fe18"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "30116a419db832463fdb008f4171c24a0e7089d5e4ad1baf55f3032041776c37"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "88695c5ebd4098b57a53d3ce6a4a5850108fc7c37a153d620cf6f3567530d7bc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41901"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c466ae64359cc298b22d26a266e81224b032547d6ec06b5da0830d7baa98fe18"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "30116a419db832463fdb008f4171c24a0e7089d5e4ad1baf55f3032041776c37"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "88695c5ebd4098b57a53d3ce6a4a5850108fc7c37a153d620cf6f3567530d7bc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40478",
      "aliases" : [ "GHSA-xjw8-8c5c-9r79" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "47563f4ad1c0608e2421f8f0d531bfd5641736dde30756a3808add09b690c59a"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c482f35011d0c6c49a218fb32491396d32f3bdff7165baba4ec0ff795ee758e9"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "abb09be7090e7e6ec18b44897af82a4c897b4e600185bb41b4fcfd73cfa5f8c3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40478 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41901",
      "aliases" : [ "GHSA-c9ph-gxww-7744" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "47563f4ad1c0608e2421f8f0d531bfd5641736dde30756a3808add09b690c59a"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c482f35011d0c6c49a218fb32491396d32f3bdff7165baba4ec0ff795ee758e9"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "abb09be7090e7e6ec18b44897af82a4c897b4e600185bb41b4fcfd73cfa5f8c3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-41901 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.5.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-40477",
      "aliases" : [ "GHSA-r4v4-5mwr-2fwr" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "47563f4ad1c0608e2421f8f0d531bfd5641736dde30756a3808add09b690c59a"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring5@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c482f35011d0c6c49a218fb32491396d32f3bdff7165baba4ec0ff795ee758e9"
      }
    }, {
      "@id" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.thymeleaf/thymeleaf-spring6@3.1.3.RELEASE%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "abb09be7090e7e6ec18b44897af82a4c897b4e600185bb41b4fcfd73cfa5f8c3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-40477 fixed by backporting the upstream fix onto the 3.1.3.RELEASE baseline. Fixed upstream in: 3.1.4.RELEASE"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6c63c52c3593d386db3737e7483543efa2ddb931130505aa6d828baf1034799a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 1.28.5 baseline. Fixed upstream in: 3.2.2 (tika-core; the fix hardens getXMLInputFactory — no 1.x/2.9.x release carried it)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-54988",
      "aliases" : [ "GHSA-p72g-pv48-7w9x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@1.28.5%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6c63c52c3593d386db3737e7483543efa2ddb931130505aa6d828baf1034799a"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-54988 fixed by backporting the upstream fix onto the 1.28.5 baseline. Fixed upstream in: 3.2.2 (same commits as CVE-2025-66516 — bfee6d5569 + fd2016ffe4 on getXMLInputFactory; nothing in the PDF/XFA module changed)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.1.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.1.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "00312b3f4f13abbbc375e8968d6fedb864b0320be947f00561a0f47ffd337af1"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.1.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.2.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.2.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "4a7085a593943385179e14a9ae2a65d90d60536bd98b911e752e178458bbeec3"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.2.1 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.3.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.3.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "156bf228b81f627973fef40612e48cf9ea799c1ad08e2601e3c46799c4fe0b3b"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.3.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.4.1%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.4.1%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "df98e6e45bb79bd28543ad6c2beee5463f1a2e3d1486d9bf47ac0dd537561d46"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.4.1 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.5.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.5.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e024ee6703de1c9651d12a5dc7bb81516adef1f2f0069fd2702b8b2fc34f2809"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.5.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.6.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.6.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6090c5ab2dda1e5e2e86ca380a1ab7c9b52cfb11c9968b958b546c9b1e570b05"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.7.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.7.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "033139f7d0712087557a0106ccd1134b9458c5346a6954890d10eebc193581db"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.7.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.8.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.8.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "7ad631520cfafda317ca45a354e952967d2a93b8a49452decc311a7b9e9ab470"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.8.0 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66516",
      "aliases" : [ "GHSA-f58c-gq56-vjjf" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "56638e346f4be02b0d28cf8d1d2b4a4b7f3f940d6539eb4e826d72a5bf5563be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66516 fixed by backporting the upstream fix onto the 2.9.4 baseline. Fixed upstream in: 3.2.2 (tika-core). No 2.9.5 exists — 2.9.4 is the terminal 2.x release, so the 2.9 line never received it."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-54988",
      "aliases" : [ "GHSA-p72g-pv48-7w9x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tika/tika-core@2.9.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "56638e346f4be02b0d28cf8d1d2b4a4b7f3f940d6539eb4e826d72a5bf5563be"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-54988 fixed by backporting the upstream fix onto the 2.9.4 baseline. Fixed upstream in: 3.2.2 (same commits as CVE-2025-66516; nothing in the PDF/XFA module changed)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2023-49735",
      "aliases" : [ "GHSA-qw4h-3xjj-84cc" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tiles/tiles-api@3.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tiles/tiles-api@3.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "c7625623d2bbbf13fc7f7af695d654ddd4d82dca84aba296bec9efd99354b363"
      }
    }, {
      "@id" : "pkg:maven/org.apache.tiles/tiles-core@3.0.8%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tiles/tiles-core@3.0.8%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "6e013428e1a581038d2a948a6d1bf77ada18ec2a8cbe0aab1949642fed88ac0d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2023-49735 fixed by a patch applied onto the 3.0.8 baseline; no upstream release carries this fix. Upstream status: none (project retired to the Apache Attic; the advisory is marked UNSUPPORTED WHEN ASSIGNED)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eb4b1d86940ad3da193e035d95f31f3710f75d26ba810947457ac295a23c5e80"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@7.0.109%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "eb4b1d86940ad3da193e035d95f31f3710f75d26ba810947457ac295a23c5e80"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8ec25ec95a53e010805ed2c72127fce59422cd791582ead8f5e2ee051895ebc6"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.0.53%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "8ec25ec95a53e010805ed2c72127fce59422cd791582ead8f5e2ee051895ebc6"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "18bc2f1dba65b6b1c072d910921a912cfb619b154d8524e3feaf8e078722e639"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line was EOL and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-catalina@8.5.100%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "18bc2f1dba65b6b1c072d910921a912cfb619b154d8524e3feaf8e078722e639"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line was EOL and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "df30e019b2c118a617dae5f1685e4a109cb8a0699c3974154d48fb84997fb3fa"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@7.0.109%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "df30e019b2c118a617dae5f1685e4a109cb8a0699c3974154d48fb84997fb3fa"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.0 through 7.0.109 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "beb1187cc841d30116eeaa9e4ec28d1f4750b537370e1ad99ba64114473ccd35"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "beb1187cc841d30116eeaa9e4ec28d1f4750b537370e1ad99ba64114473ccd35"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41293",
      "aliases" : [ "BIT-tomcat-2026-41293", "GHSA-r29c-68gh-xp6x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "beb1187cc841d30116eeaa9e4ec28d1f4750b537370e1ad99ba64114473ccd35"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "8.0 has no HTTP/2 implementation; the shipped jar contains no org/apache/coyote/http2 entry."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66614",
      "aliases" : [ "BIT-tomcat-2025-66614", "GHSA-fpj8-gq4v-p354" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "beb1187cc841d30116eeaa9e4ec28d1f4750b537370e1ad99ba64114473ccd35"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "The CNA states nothing below 8.5.0 is affected; 8.0 has no SSLHostConfig, so there is no second host config to redirect to."
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-1938",
      "aliases" : [ "BIT-tomcat-2020-1938", "GHSA-c9hw-wf7x-jp9j" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c5e2f7c0569fb472c00d94490c3b47ebfee3db72712bafa1cff95b60bcf11076"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-1938 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 7.0.100 / 8.5.51 / 9.0.31, of which this ships the code half — the block on the vector that returns arbitrary files and executes them as JSP. Upstream's other half hardens the DEFAULT AJP connector configuration, which no jar can ship and which this baseline can already do by hand; see notes and known_open_cves is deliberately not used for it. The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c5e2f7c0569fb472c00d94490c3b47ebfee3db72712bafa1cff95b60bcf11076"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c5e2f7c0569fb472c00d94490c3b47ebfee3db72712bafa1cff95b60bcf11076"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.0.53 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.0.x line EOL'd in June 2018 at 8.0.53 and received no fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-41293",
      "aliases" : [ "BIT-tomcat-2026-41293", "GHSA-r29c-68gh-xp6x" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c5e2f7c0569fb472c00d94490c3b47ebfee3db72712bafa1cff95b60bcf11076"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "8.0 has no HTTP/2 implementation; the shipped jar contains no org/apache/coyote/http2 entry."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66614",
      "aliases" : [ "BIT-tomcat-2025-66614", "GHSA-fpj8-gq4v-p354" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.0.53%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "c5e2f7c0569fb472c00d94490c3b47ebfee3db72712bafa1cff95b60bcf11076"
      }
    } ],
    "status" : "not_affected",
    "justification" : "vulnerable_code_not_present",
    "impact_statement" : "The CNA states nothing below 8.5.0 is affected; 8.0 has no SSLHostConfig, so there is no second host config to redirect to."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66614",
      "aliases" : [ "BIT-tomcat-2025-66614", "GHSA-fpj8-gq4v-p354" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66614 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.113 (also 10.1.50, 11.0.15). The 8.5.x line was EOL and received NO fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-32990"
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-32990 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.116 (case-insensitive comparison; also main/11.0.x/10.1.x)."
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-66614",
      "aliases" : [ "BIT-tomcat-2025-66614", "GHSA-fpj8-gq4v-p354" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "4a225febfa55924ebb544d43ed6939b486870ed0ca379d3e6e231149f717b475"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-66614 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.113 (also 10.1.50, 11.0.15). The 8.5.x line was EOL and received NO fixed release."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-32990",
      "aliases" : [ "BIT-tomcat-2026-32990", "GHSA-8mc5-53m5-3qj2" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "4a225febfa55924ebb544d43ed6939b486870ed0ca379d3e6e231149f717b475"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-32990 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.116 (case-insensitive comparison; also main/11.0.x/10.1.x)."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43512",
      "aliases" : [ "BIT-tomcat-2026-43512", "GHSA-h6fc-48rj-7qqh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "4a225febfa55924ebb544d43ed6939b486870ed0ca379d3e6e231149f717b475"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43512 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line EOL'd at 8.5.100 and received no fixed release; the CNA lists 8.5.0 through 8.5.100 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-43515",
      "aliases" : [ "BIT-tomcat-2026-43515", "GHSA-5m62-pw8w-7w9f" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "4a225febfa55924ebb544d43ed6939b486870ed0ca379d3e6e231149f717b475"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-43515 fixed by backporting the upstream fix onto the 8.5.100 baseline. Fixed upstream in: 9.0.118 (also 10.1.55, 11.0.22). The 8.5.x line EOL'd at 8.5.100 and received no fixed release; the CNA lists 8.5.0 through 8.5.100 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2026-29146",
      "aliases" : [ "BIT-tomcat-2026-29146", "GHSA-h468-7pvh-8vr8" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.tomcat/tomcat-tribes@7.0.109%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.tomcat/tomcat-tribes@7.0.109%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "06baa06f4af1eb25f61295e71c3d5948d84fce1198da06ceb886de1e5913cde9"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2026-29146 fixed by backporting the upstream fix onto the 7.0.109 baseline. Fixed upstream in: 9.0.116 (also 10.1.53, 11.0.19). The 7.0.x line EOL'd in March 2021 at 7.0.109 and received no fixed release; the CNA lists 7.0.100 through 7.0.109 as affected."
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-3629",
      "aliases" : [ "GHSA-rf6q-vx79-mjxr" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/io.undertow/undertow-core@2.2.3.Final%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/io.undertow/undertow-core@2.2.3.Final%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "f2b5ee1c3ced0f80281e17c2ae8f6ca363af9a24245ec30c78939b164320fc6d"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-3629 fixed by backporting the upstream fix onto the 2.2.3.Final baseline. Fixed upstream in: 2.2.11.Final (also 2.0.40.Final on the 2.0.x line)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-13936",
      "aliases" : [ "GHSA-59j4-wjwp-mw9m" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.velocity/velocity@1.7%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.velocity/velocity@1.7%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "91d7cff0f9214ad751c0a482bf4da922159b9d418620fa3515a567a14a06f7f0"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-13936 fixed by a patch applied onto the 1.7 baseline; no upstream release carries this fix. Upstream status: none (fix shipped only under the new velocity-engine-core coordinate, 2.3)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2020-13936",
      "aliases" : [ "GHSA-59j4-wjwp-mw9m" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.velocity/velocity-engine-core@2.2%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.velocity/velocity-engine-core@2.2%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "e0319b83446502951b4bcde77938c3eca910f1990ee531d6f053f0cc42757bbc"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2020-13936 fixed by backporting the upstream fix onto the 2.2 baseline. Fixed upstream in: 2.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2012-0881",
      "aliases" : [ "GHSA-vmqm-g3vh-847m" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d672c963a3e7926f8a848721d667030404961dc971b269220226842aac0ea29e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2012-0881 fixed by backporting the upstream fix onto the 2.11.0 baseline. Fixed upstream in: 2.12.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2013-4002",
      "aliases" : [ "GHSA-7j4h-8wpf-rqfh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d672c963a3e7926f8a848721d667030404961dc971b269220226842aac0ea29e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2013-4002 fixed by backporting the upstream fix onto the 2.11.0 baseline. Fixed upstream in: 2.12.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2022-23437",
      "aliases" : [ "GHSA-h65f-jvqw-m9fj" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/xerces/xercesImpl@2.11.0%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "d672c963a3e7926f8a848721d667030404961dc971b269220226842aac0ea29e"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2022-23437 fixed by backporting the upstream fix onto the 2.11.0 baseline. Fixed upstream in: 2.12.2"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-23926",
      "aliases" : [ "GHSA-mw3r-pfmg-xp92" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.xmlbeans/xmlbeans@2.6.0%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.xmlbeans/xmlbeans@2.6.0%2Bbackpatch.001"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-23926 fixed by backporting the upstream fix onto the 2.6.0 baseline. Fixed upstream in: 3.0.0"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-40690",
      "aliases" : [ "GHSA-j8wc-gxx9-82hx" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.santuario/xmlsec@2.1.4%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.santuario/xmlsec@2.1.4%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "34a9763ac9c66731b31f7d177fd68bb0c882c2710a4c5b3524fadd7d579070b4"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-40690 fixed by backporting the upstream fix onto the 2.1.4 baseline. Fixed upstream in: 2.1.7 and 2.2.3"
  }, {
    "vulnerability" : {
      "name" : "CVE-2021-39144",
      "aliases" : [ "GHSA-j9h8-phrw-h4fh" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/com.thoughtworks.xstream/xstream@1.4.17%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/com.thoughtworks.xstream/xstream@1.4.17%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "82437b8bd37ed9a535804afef35289b9dcdab0f695a8a827bf2a6389cccff725"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2021-39144 fixed by backporting the upstream fix onto the 1.4.17 baseline. Fixed upstream in: 1.4.18"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-68493",
      "aliases" : [ "GHSA-qcfc-hmrc-59x7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.001",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.001"
      },
      "hashes" : {
        "sha-256" : "ff9e3d073130c7828346373da3f9560c853f323aa2a5b53e75386d7441e550fb"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-68493 fixed by backporting the upstream fix onto the 2.3.37 baseline. Fixed upstream in: 6.1.1 (nothing on this coordinate — upstream's remedy landed after xwork-core had been folded into struts2-core, so the standalone org.apache.struts.xwork:xwork-core artifact never received it)"
  }, {
    "vulnerability" : {
      "name" : "CVE-2025-68493",
      "aliases" : [ "GHSA-qcfc-hmrc-59x7" ]
    },
    "products" : [ {
      "@id" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.002",
      "identifiers" : {
        "purl" : "pkg:maven/org.apache.struts.xwork/xwork-core@2.3.37%2Bbackpatch.002"
      },
      "hashes" : {
        "sha-256" : "8ce5bac3d21cba3eaec11bffa17f31e27aa8c46d43343ec0740d2d9ad17d4a18"
      }
    } ],
    "status" : "fixed",
    "action_statement" : "CVE-2025-68493 fixed by backporting the upstream fix onto the 2.3.37 baseline. Fixed upstream in: 6.1.1 (nothing on this coordinate — upstream's remedy landed after xwork-core had been folded into struts2-core, so the standalone org.apache.struts.xwork:xwork-core artifact never received it)"
  } ]
}