{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f6f89c84-6fea-50b4-8483-7e4abb61e6e0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-instrument",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1",
      "version": "5.2.11.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ff5e1115-33e2-5c27-aec7-a727c5c051b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:92c49595-7fc1-5a03-9a5b-9b7009bc2fa2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2e3a43a-0e7f-5169-b8b4-2a7c7123a90e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75f6ea49-141a-51d5-bf44-33c053bfa0ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f13492ef-ed27-5ad6-9f95-b2e7f149ce1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ccf32f6-992c-55b3-9144-41bbde68ba76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:025705be-a324-550b-970b-72852379a095",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ad98992-7c7f-5a88-be13-97bb23c30205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a83d3dc2-7102-5629-a61a-3a5d1c66c756",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:378325bf-118d-5fb2-a9b1-114434886e74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40a60ef5-f2d4-501c-89c2-bc76255f6bad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f792e4eb-73d3-5431-b355-03b975504e80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d7ead3a8-ba7c-5a1a-a88e-5540e055cb06",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c3bf5452-a7af-5c3b-91d9-5683e317edf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de3b7e55-8509-56e0-8c70-be1510b77318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48a092a1-6afa-5280-8ec5-a8f452acfb17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01f97302-7eee-595d-8c39-17643a34fbc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4c767b3c-9225-5ce3-a9a3-bdf18bb97577",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79e0c19f-d70a-5788-b183-c0d2cc9856ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8b668e0-64c6-5c24-9f1b-a469159ec33b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b044633a-cb32-54cf-ac42-a078baa0c752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4170c0f3-4bae-580c-84a0-7719cb088a83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06c32c9b-b962-54cf-86a7-6b9d8fd54244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7c24518-6ca6-5ae8-9316-5c3538e9177a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d807926f-c410-506e-ab51-6ea3bcf9d0f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1154776-9b1e-5d45-ae47-e66716c10465",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4337698c-fba6-5525-8100-9918bc5fa1a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b54f54d0-8a0d-5048-95ee-02e8f774b576",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e891d9d-d780-542e-9847-194b2851709b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b73e47d4-1bad-5f16-8fdf-1bc865bbaee9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac28f5a4-fa9e-58b9-a0c2-dc0c0e7d7388",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f307554-9c6b-5f5d-a27b-52f9cc568c31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f98de0ab-a1fe-5f74-8954-d4f020c74402",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:628a16d8-c234-5736-b60d-5b22fe1c9c2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:034e223e-1361-502d-8d46-d07b78b32909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1aa35391-80e0-560c-929a-38014c9ef9aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:518cd776-c7f2-54a1-a089-aa7b0c2ac37c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16eb5ac3-7c8e-57ef-8044-78d51ad44d62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b57a7b6-902a-5c76-af45-6346ef169332",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:68e515a2-a39a-5df6-aa18-74ebf68f4ea8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27e7d930-b580-51b0-a1c1-76b08bbda39b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36d0328f-c297-5227-9a18-ab822365ef94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba7da25d-1b5b-55b2-9aa6-5a7332d59050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18106425-3ab9-5ff7-9e6e-e4aa4225f42a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:011f2b51-dad1-58ed-8ed9-57bac8dadb0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:261da723-9bfd-5553-a0b3-8b4b1277e92b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec414127-8128-5cf6-83fe-3f5d7be79523",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d52d617-7231-5298-9d50-c6214262e590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ceaf86c6-ba96-599f-ab55-bf4b776e3f87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9dac497a-3681-5b4f-b82b-911d997c1cca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3f72b5c8-6274-52f2-b7ac-17fd9640f32c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70758c45-45a9-5c2f-8538-b14b99a1481f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e96fd271-bbb3-5326-bf62-9da3a5a43bad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:43cf3bb5-f169-5070-9664-388d1359f235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56657a95-a389-579a-914d-246b6b5b6ac2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:11c5173d-8d11-5f79-964e-476ce2984829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cefde350-250b-5200-ae12-ab4ef707b703",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.1"
    }
  ]
}