{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b56107a5-39af-53a9-ad38-e546b2e65207",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.1.20.RELEASE-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:217593ab-df44-5881-bef1-163eef2355bc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74fc209b-d950-5376-84eb-fb97aa770159",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f528d26-4e7d-5cce-9b5f-c9e45ab73852",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d20404-5f70-53ff-966d-0156cb731624",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e7d9336-a7b5-5bf3-a782-3e9d37065548",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b56be4c-754b-59fd-9fe4-f1d1a274eb21",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34c4355-306c-5bd0-885b-3879f601f498",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4df8f9b-3e30-522e-a6ea-608a84bc57fc",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d514d827-665a-596e-a80d-19e685265d57",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d44f3e0-f635-5ade-b649-97d256761e2b",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70dab473-871f-5c0a-ab8f-7e77b146a18f",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f97272-41ed-50f3-b91b-320c4a57f1e3",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce07d017-b340-5c96-80b6-0ec620e2636a",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241419f0-5140-5460-a7b6-e4761649af98",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d516543-391b-5cea-a114-349083caa01f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a4686e6-67fb-5ab8-af45-2fa6cedb33a6",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-instrument 5.1.20.RELEASE-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544a1e0f-c396-5e7a-8ad2-35cf456ff71f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e56763fb-b1ee-5a3d-a17c-14767c885960",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d07f4d-dc79-5781-9cde-b3009eea61d2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315d43a8-3bbd-5f50-845d-2cfb513667a9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48acec9-82f6-5ab8-b87f-eb3ed7eefe9f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a9c5ce9-cfee-5def-b70b-01873c002d89",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d80adb72-94ad-5048-aa51-b91fc2f18df0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7fd3f12-9c9d-5d74-be22-d356d963b527",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0332cb9b-d2e4-547d-a9e9-c7c5c54585b7",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55297730-8c32-5f6a-a36c-baf31e69ff74",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e2d5e7-4bb0-5fe7-bc8a-74ec6cc818e6",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5871d766-e422-5f36-aea6-000430e117c5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ca3457-9ba6-5c0f-94e2-178a80d768aa",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9fc3184-bb26-5f56-a958-863cf1e380d4",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24fb986c-e289-5433-a90f-d621645025bd",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e4ce7c0-d644-5398-be79-14163adba8e6",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e04c817-99c6-5696-9ac5-5427f1edafad",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf39559-b324-5fc0-9afc-c564d504530d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8043b00b-9595-57ce-afbe-ee86861c6723",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba5653c-cdad-5daa-b10e-74ddb23c6ad2",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f89f38-0331-5e91-adcd-4e08d5214528",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b68e3fce-e951-593e-b53f-291a23d01373",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f65751-54c9-5cbf-9aba-d8b499816848",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3f84fb7-0374-59ac-b603-22815bec7edf",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08180595-c86a-530a-bf05-e76c4b14cda6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad20f9ec-0144-57d4-b42e-322b9c8b2f86",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.1.20.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.1.20.RELEASE-tuxcare.2"
    }
  ]
}