{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9fcd36a8-f9cb-596c-a8e6-fb5b98f26318",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "6.1.20-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:411952aa-dab7-57de-87ff-614b15aa4d88",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e5202f4-68e1-585e-bca2-d2165e8cdac1",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6dc080d-0178-5e8b-b8d6-930bb0a71879",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2cc411-0ae7-5fe3-a84f-a3def7aa8c22",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6ee2571-77ad-595d-8b02-e5ab5f498fb2",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a212895-8b4c-5232-9f28-35203037ae70",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28efc886-fa55-5f9f-930c-5b08f45e67c8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d2bfdc-6f2d-577a-b2a2-c6aaa97e4528",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f01a5ba4-8028-51b3-9346-8524f91c91c7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02315107-09ce-53ac-8b41-907392145b48",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d864638-5c1f-5a27-bea3-2be7e934a4a4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46cf8bdb-96b1-5701-8e48-153c17029049",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d832a49-3838-542a-b0df-aeb0fb2b648d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.4 of org.springframework:spring-instrument. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9162ef36-c0d8-504e-a79c-4d306073d4e9",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b402be8-8c75-5365-996d-dad683df11cf",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f09d9a-915c-5bd1-8a27-2905a698057b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3031cf2d-11e6-555f-9856-8effc50e7017",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:190b9d7c-d83d-5943-8054-dcdf910d2c0a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9275d996-fb22-586d-bce3-f4fab0d1e5ad",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4b0eac-1546-51bb-8a1c-169d4d26a636",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956df802-6f51-5044-b16d-b8d46ae88910",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c50f99-7423-5c0b-9bd4-28985b149ade",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b131d759-708f-52b1-b41f-3e855b5a6ebc",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d75c661-11a3-5988-a1b8-23cf7ecac08e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08be14c0-39a6-5e2c-8ab5-dce636ad1de9",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.4 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.4"
    }
  ]
}