{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c9487cda-eb81-5fd4-9581-c45f6fb5d351",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-instrument-tomcat",
      "purl": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9",
      "version": "4.3.30.RELEASE-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:58f64bf2-acdc-5e8d-af39-34e7457325ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dc42f52c-4635-5286-b6b3-d82880e836be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c1c62f98-b785-5c20-ac3b-2c049d1419b7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1707e78d-1a2b-5337-8001-9429ffe7aac7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7223cf55-09c4-5453-ae16-1b37cc7d9a4e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6bdab060-99a7-5d8b-afd6-12b0bbc5f30c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ba94da6c-999e-53d1-8c89-9205dcdc2029",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ba349552-a4f1-56b1-b6f8-5ae3821fb735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ce53a599-0fac-5894-b38a-80290a6be5ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9c5103ee-b41e-5267-b91e-8291a76961c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2eb096b3-f21a-54be-b70e-8bb3897ec6a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c40f945e-9f56-5eb3-8965-d76f71819490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0b93ddd4-f5ab-5f26-b2c3-469ab8bcc75b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2a25ae5e-09b1-5e6e-bfb4-7e35451fde01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c12b104e-c3c8-5270-993d-d2cf8ca3059e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d9024280-88ca-59f8-b393-cfffd0e9e238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f13663e4-735f-54fb-9ca3-f30a28f74335",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:308de4b3-8b62-53fb-8836-350f7f3cd375",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5a6a5fff-81c0-5f36-ae4e-6efd05845c13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c9c18981-f2a2-5c5a-96a5-cfbe1b0cbb02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d16581c7-da04-5bd4-b8a6-3d9f4f81f676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5d9423f5-2374-52b6-9099-e06604d3bfe9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fd772b22-84f7-5a26-b3f0-6502eae5533d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cdcc686c-4104-5bc0-87ac-a4dea9e780b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:29ad53e1-7919-5b35-9656-0882e4a18f22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d545c075-f0e4-58cb-b250-22e208cb7fe9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:085df249-e9f3-5481-989b-c51eb66c7774",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:548487b8-0b6a-564e-8eb9-5f181d0127c6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3c06a3fa-c8f1-5a5b-adfc-3b5604a1c316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:81e4584a-a2f0-5cf2-b557-d6cf0dca9dd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dbb259f3-4464-5a6f-b360-705242258e12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4604fccf-22e7-58c8-b9d4-a1a910e0ce02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:276c2bfb-615e-51c9-9e88-a969194fbddb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ea4875c8-060a-5c95-a050-472583e29ee8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d0c88b19-fdd9-51f1-9f33-ec56e426e4ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5849b3fc-25bb-5195-a39a-840636e735cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a3e1ff52-851b-56dc-aa66-e33d290ad095",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4b0ded90-6fb6-56a2-b617-18c6b23a9598",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7fff2b61-2d25-58b3-87b8-d7a725c6cf90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:06f47905-6a3a-531c-8fbf-78141deb6110",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ea98705c-ee37-589b-b469-d783d8e1baba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:65c839f4-e76b-597b-85e8-23333e9507ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:78acd775-25e3-5b52-b01c-b5b3b075cbd0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8b801c2a-7324-5b8d-a900-56dc93a62ba3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:53cfdfd7-c4e3-5941-81b2-216cdd98073c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6c84c18b-b1b5-5f35-abae-077611d25563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4fd410f9-b5d1-5dbb-8321-d225fc7ef62e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c5066e67-5adc-549b-a3e2-8aa27ebb05b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2f7db21f-9489-555e-b164-42b5174927d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:82abf4a5-1ebb-50e5-8652-b571ff18edce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0c12bbc8-13e9-5d0b-8ff1-943ab704673a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d23b545a-bb59-5ca1-a470-ce29c5b7eea2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9b1bd563-aadc-57e3-8bd7-622949f10c16",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.9 of org.springframework:spring-instrument-tomcat."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.3.30.RELEASE-tuxcare.9"
    }
  ]
}