{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af3399e8-cfe1-5217-afbe-158c64441832",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.3.27-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bb839cf8-618b-5505-a3df-3b984c022bdc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544a20aa-81ed-5ee2-a092-c686ab7fbaca",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebcbd672-6e63-5c9e-bb4b-cb237dad7493",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14c011d-ed32-5062-91df-d6d2caaeafbd",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a56e6fb-d536-5798-883c-d49f20c97331",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6dd93a6-b1c6-5e35-b81f-abbdcdf39aa1",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee37ba44-9db7-5639-9b4f-a20e09e6303c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b31c2a-f023-5b7c-9fa1-9ace77b69f7b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06dd5af6-267f-5b7b-9ac7-f206a9eeae99",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40f2e2ae-544a-5209-be5b-3e8b9f6a620c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05c9c657-2a0a-5ae0-adbf-10c5687cb2e4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed48d3ed-5183-573e-9fae-f36e19831318",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-instrument 5.3.27-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c3f6100-3463-58ce-9c29-df72eb17b1f2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69842b18-cebc-5e79-8403-fd0d015900c2",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8695f42-90a3-562e-8936-a08a3c5a626f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45945fa2-f25a-538d-b595-67532eff445d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c7572ec-5bf1-513f-86ad-36dc575c6b45",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb00ee4c-7369-5a1a-87f6-2a2219807109",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0efaa6de-d505-5474-a851-440a022dd262",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02d38767-6132-5279-be4d-890c398b482d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a7fceb-66f9-51cc-8a54-32a205fb3b63",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11dd002e-be88-52a7-994b-38cc776c9c07",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9287bfa-a44a-5718-b048-7eda184249de",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-instrument. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b346080d-5ba3-5e09-a02e-f95dc491b38a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6be428-df61-5b9e-9cd1-05fd8a43fc49",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49bc424f-9f18-584f-9645-01b91991dfa2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2af0d4-30ee-5d6b-a694-f44dd595b7d8",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c671ac0c-328d-55b9-8b31-66e0c000960a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:157ad6ae-b2b2-58ec-8778-bef3e46338fb",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e794ce2-3f4c-5c07-a332-0ba4e4849a62",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-instrument. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d240c13c-019c-5c61-a236-a04223532f58",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd32eac-09b3-5015-8e30-c2e5021e9dfc",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03709fbe-8191-5791-9794-99f2a2cc71e7",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14da564f-e8a7-56ef-a997-3f812a4c20fe",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda34917-7e26-54ca-b6fd-2f80ad6181d2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d8021e-9ec8-56a2-b7ef-6c4ed31577c6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca21158-a24a-593e-ae63-b28f08eb29d7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.3.27-tuxcare.2"
    }
  ]
}