{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c7451da6-695e-5a62-bd22-763c9fc5c00d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.2.13.RELEASE-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d2c74093-8a2e-5491-ba55-b00d6f844850",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c49b86f7-4e07-5461-8073-8d707cb0b5c1",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e943ed-607f-5def-9ad7-a38fba02a2dd",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d10cd945-9675-586e-b2c7-edd3028597d4",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fcaa126-89b1-53b4-968d-01868fed210b",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b8d954-f094-50e4-8d9f-1eef677b56b4",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01287c7c-6e9a-56cf-a6a7-c1c4a9d8249b",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc0cdc6-5e0c-51ff-9ebe-0ecb5ec5ae1c",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da0604cb-d4dd-5b12-a645-946e2d747b89",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa911d94-0b2b-5fcf-9e6e-59e12dd6e626",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c7d2ce-ccf5-596f-9d30-67260e11be2a",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7efb4677-2124-50e0-b1a2-a44a27f1b0aa",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070a142f-0d0f-5d8b-8636-80660b17f881",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c9dad3-e0e0-5e71-8268-bc27810a0e67",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1234b8ee-8114-5865-9add-7afe5412d7fb",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9033e905-2c9f-5ecf-925e-f5ac0f92aae7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe34f4ed-ace6-56b0-9aa8-b3a9c7f3fb70",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e426c938-f02c-5329-a662-b4ad2a11d248",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae7aefda-63f5-5d41-9cb4-8c44a456992c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f663e578-909b-54fc-843c-465004978928",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa93534-82ed-5f8a-8d5b-89df001f6f4f",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41234 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:841503ab-c662-5ce0-ac7a-1d4f9670f42f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bec698f-9de1-59c2-82cf-3ae82f9b0f98",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bda329d-f3a5-5437-a20b-91b2112a4545",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15dbee10-f301-5900-8254-d923dd552c01",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae8ee46-e5c5-5594-80a6-402ea80ce5c3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06e062ca-7245-5fc2-8483-a53f5e842c3a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb7dbbf-93b1-5a1c-b3cd-48421f51a0dc",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe71d9f8-42e0-5759-93b3-b9c577c83056",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument. not_affected \u2014 Version 5.2.13.RELEASE uses a fundamentally different multipart parsing architecture (Synchronoss NIO library) that does not contain the vulnerable components targeted by CVE-2026-41840. The CVE explicitly lists affected versions starting at 5.3.0+, and the patches fix issues in PartGenerator and MultipartParser classes that do not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c9c4bd-736d-5d51-b7ee-e00f10f0f3a2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ae4285-bb89-5e76-8c1f-027f06d9b851",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61fa0daf-9b67-536e-b503-ad3dc3e7aa57",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:484e28bb-932c-5cb9-a2ba-5dc39d4804b9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b420b8c5-fce4-5550-a428-5ae49a8f1820",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f0ac920-0564-5202-8c0d-37a973ee170a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7546640c-ea89-5d04-91c8-2dad2208049a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9daf32ec-16c7-5002-b2d3-aff2cec63588",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76546af1-6b83-5da1-a87e-c574bfa9bbda",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:714d8f41-7355-57fc-a2cf-03dc7e7c5cc6",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa438e8-3340-5465-8799-da77a4c52e1a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:686d02f9-cacf-5ab5-a696-4eb4c8bba7f8",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3107caee-0d31-5183-af63-074399b1c123",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:204cb194-45c4-5498-b3f9-a427075bcb07",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.13.RELEASE-tuxcare.3 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.2.13.RELEASE-tuxcare.3"
    }
  ]
}