{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e331b46d-1253-5f98-a6fd-f1e92390260b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.3.31-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:309bfd5d-0060-5250-9374-8341420d3adb",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb2d11d9-44b0-586e-a2df-951cf303e8bd",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb86436b-2b5e-5fa5-a91c-5f58a6fe3887",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8822b8a9-20ee-567c-8e12-09270980a367",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41cb2ff7-b870-5487-a9de-e167040f06bc",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5fd60ca-1dd0-5fd2-87b5-b029c33a2b77",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71aba5a6-e91b-5bab-9fac-15e8f52fb271",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a1bb3df-9235-5496-8a9c-a116e5328dbd",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cc636fd-8b9f-54f6-9481-0863af7ad323",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f37419cb-d857-5b62-9254-5137c4a4ec1e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c940113-98c5-5a9c-b44d-e5dbebd03535",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74024db1-6aad-5699-89f3-c4be8d304eb1",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-instrument 5.3.31-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec2e805-cff7-52b5-ae33-2de76e313e0c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8986f30-66ed-50ab-aa74-f96f6df529cc",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb91659-b05a-57cd-b882-ed41c2cc2600",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b9ebe18-05ef-5fea-ac92-4f371b1d98f3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21e5d726-0521-512f-a348-81c7274c2da7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76315103-7154-5dc4-96c7-77d2b038152c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e1b7731-56ab-5892-8e0b-f36a23a0d93d",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d90c218-0b66-5c15-bc93-14db80eae462",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2628a971-7b08-54fb-a573-c9e7d302df7d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2375d201-69f0-5514-8414-e7b01c2823a4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14c131c-702c-58e7-8b7b-affc2fd26587",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.1 of org.springframework:spring-instrument. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d63b34-6f84-559e-9ced-498e25124378",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee14bccc-f4c6-51a9-a1ce-1ede8f030da4",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:642da93a-b771-5fa5-98ab-4325de608ad8",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbf9c271-b118-5333-afaf-fd7788e98432",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d54f3fc-b021-5a67-abde-b1d06b23bacb",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9364a58a-9966-5372-87ee-f8d4a58fa4fc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecce4e02-8171-57e6-802f-0daee248f86b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c78aa8ea-db1a-5b55-a2cb-fd6796f45124",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:180b84db-4f33-5574-a13e-d017e7203574",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b07551b6-0b30-53c7-a8a9-6fccd04416fe",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070cdc57-0411-5be1-9544-6e5f3ad40112",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a103d28a-3722-5f04-811f-ce496464cd02",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e3e8938-ab1c-5616-a220-2a1eea44bad0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99e0355-65b0-5c97-a3fd-f50102031ee2",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.1 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.3.31-tuxcare.1"
    }
  ]
}