{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d702d6fa-efcb-5822-9de6-a3e493f610ff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.2.13.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5252e27c-2568-5260-8548-fe81e51d3340",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26fc21e5-9c64-54f5-9ea6-017a16487f51",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dd4e883-d742-5181-b59a-a04f2d22a16c",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d48dce-dfe0-5157-825f-a93db062535e",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b52d94-a939-5115-82cd-42bf234648d6",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fdee42a-b6f7-52c4-aae6-6a2865dff1b9",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:513723e1-3b1d-5d66-b866-91ffbcad6780",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3f8b162-81f3-5e18-9157-c15ab73f2e73",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:383fc97e-0192-5621-b848-0587a5dcc9ed",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:650bb92c-3fff-57a5-b7df-8e692fd576d1",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:303523ec-8752-5f8f-aab3-f3bf022fc4b9",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a83180e2-53d2-5305-97df-c0c82c91682f",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14e4088c-4e75-5755-a660-e0e21332d042",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d715dcd-d0ff-5828-afa6-2db1eb47d662",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9ff603f-3005-59fc-8326-9ece4c6fd775",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2be70a6f-abd8-55a9-b266-b9b4ab55076c",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a77c731-eec2-52b1-aa5e-afd5ddd1a9b3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f132327-1d47-55c5-add8-e785a604afe9",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b94fe26-5ca8-5b13-b987-43708022dfbd",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0babe124-b01c-53c2-a75d-24e711627b83",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c02674-a870-56b4-af03-07447ee7acfe",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41234 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6575cc21-0cee-58c5-b8d6-e98e124b2747",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d4631f9-7502-516e-bdfa-127321560d8d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b0647f-5b81-5a0e-97ac-8a87b51387a5",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd7bcde-6b8c-5bd6-be25-5040f281ea0b",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:159586ba-0629-5cf1-b62a-ad566b61d1aa",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fee5ecb-4376-5b3a-9097-5d875a5e4e80",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c155720-3f2e-54bf-9acf-400e14b3aa0e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21791e5c-10db-5593-a454-f7f09ba6d0b3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument. not_affected \u2014 Version 5.2.13.RELEASE uses a fundamentally different multipart parsing architecture (Synchronoss NIO library) that does not contain the vulnerable components targeted by CVE-2026-41840. The CVE explicitly lists affected versions starting at 5.3.0+, and the patches fix issues in PartGenerator and MultipartParser classes that do not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb04743c-c477-50c3-8f83-37251df2d978",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd045f2e-d4b4-5ca3-bb19-2a5a9ece3cd1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84ef6265-f792-5f5d-aef6-7dbb3096e71c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4bc968b-943b-5cb2-956d-c6c6a1a99bf9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20db8629-0d43-53d3-b071-9063ba6f4357",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a985e4-dbd9-56f1-82fd-b4954da8a331",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543b5cd6-d85a-52db-9c31-ff7eb51727f2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:595c78f4-a73e-50fd-8f7e-770775f4799d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4279380f-a1e1-528b-b229-0ae0544d61f9",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd82b7cf-ec04-5773-8c2a-c5c7b04431f4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7e33283-e8dc-5d3e-8362-9d73de14d5e4",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e94e8c05-d920-5786-85aa-740edfbe63bd",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3eb29ff-23a5-5294-aa87-5ffcc454275e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f0d623-1114-530b-becf-7ec9ef779a02",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.13.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.1"
    }
  ]
}