{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7b48880d-6619-57f0-9307-8e73a75a103c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.3.30-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d7bd6f99-dcd5-5ab8-bcc9-6d0012ca74d7",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:244b7d82-6813-5ef3-8748-d10bbe1d0d73",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:865c3a81-007e-50df-8875-8005fe21398d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:075e2241-1d83-57f8-854e-246e8559406a",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb6734b4-1caf-5026-83d9-992b578bb0e4",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a774f077-9c04-5838-b076-3bfe31c2d971",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f6f99b5-e56a-5c68-8f36-0d61015db933",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b65137-82f7-55cc-ad88-79544a2a6e4d",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ed1774-bb31-5ddf-a27a-8ad65afa9ae6",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8086bc8b-7cc7-5c94-b1a1-103de7755f9e",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0795cb3f-6b39-5a60-8ba4-6e39407a8b43",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bb7fd55-4557-51fe-9312-0f8e52f42fd8",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1380110e-e6e2-5cd6-b9d2-5395bcd496e4",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:468adff3-4808-5601-b162-bf054cc99324",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0dcd6cc-da21-50c1-bf08-bb0cb689e42b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cca3e1b-9847-523b-b0b9-0ce4880ca8d5",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e7259d0-cc65-59bc-bf9a-9bffe3b6beaf",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e97e82f-d97b-5fb8-b65e-92adfc7e5085",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a59bfe-b4cb-5c39-a0e7-92961bbd19c3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6467e85-e5c2-54ff-a99f-952c8ac42055",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ba7a56-1144-5e9f-8668-3ed0e26dae61",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79a9af12-a70d-530f-b85c-187046aa3496",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.2 of org.springframework:spring-instrument. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e5537f0-c165-554f-9280-bbd55b02e0ec",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36560620-060c-50a7-adec-3b2712b76fed",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2df4e08-ec8b-5a34-a733-fc7c30eea2d5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a065e612-32f4-5fbf-b13e-08f523fd391c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d16ef561-6c17-5659-985d-7b9aa0cf1cda",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71e57dd0-3014-50a2-8054-7fbf7db57267",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e0d758e-c605-58c7-8119-c140807d8a24",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bfcf9b7-7c68-52f5-9674-d36de5341743",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c557aa7-ef71-5ca6-b8b9-24d11c1789b0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7329e02-6e71-5570-bae2-20ae31da71ad",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47fdec68-4518-5917-b1e6-3872a6f642df",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92cc8ef3-cc47-5c03-b761-4f7dd22283cd",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7b465f-035e-5f97-930f-17658323ca88",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9083631-3d14-5933-9fe1-5523f45a0900",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.2 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.3.30-tuxcare.2"
    }
  ]
}