{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e10d4ff5-7a84-5029-958d-f55cb51bc3ae",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "5.3.39-tuxcare.13",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7701cfde-b2c1-5f64-9747-2a4dd3ab12c5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03e3a98-1a23-522c-aa91-1325669f3b7c",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-instrument. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7386b8fd-68c0-530e-ab40-5b426d667506",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4085dbbb-aeb7-5047-8797-a05bfe923535",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1081c7d8-4bd4-580f-88b8-25b94838c06f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f88e0ecf-fc1c-5ac4-a8a9-fddfa0fc6a27",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ae9a9c8-f5a7-51f9-a930-7dad456ac376",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:329ec7de-8bc5-50eb-ada0-286b9b8be322",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-instrument 5.3.39-tuxcare.13."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d36b9f0-ead7-5624-b4f6-a2b0a5d3b65a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c611184-bd6d-530d-8797-dc35b996b07d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33067229-850c-5976-993e-c9d38b00773d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c884bb7a-f57b-530b-87da-43c75daf475b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b38552d9-32f5-517c-8f59-0b73a14d60df",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:316b2333-f3b9-531a-b117-a1792b552e63",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94aa22aa-3d71-5241-aefd-4c3df7946ef0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b32ce98c-b1ae-588b-a608-d56348073f2f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab23be88-df66-5983-8dca-1d640d8ae60f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab3f72e-f5eb-5a74-897f-3d58ac7a2d60",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b690832-db2f-5af1-895a-592e66d8402f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-instrument. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab0586fc-59f3-5b5a-8218-7ee3ecad280b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f017c1fc-6a53-54a8-aa00-0fbfcc88754c",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bd42cd8-b180-5fa6-be37-e82b9c155047",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c0f4191-84c6-5961-adf5-f879af0bbbd1",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2383e54b-7a94-5895-aa93-15d4a8f7c16c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1fb4e36-644e-5b5a-b304-55d511c45bc2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419eb077-dbf9-5629-803c-891a99dfa01e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6bd85c-7926-56da-920e-875e5d34a7c3",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf88c39f-18f9-590a-844d-a20e7f380dc4",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:286fadf8-75c0-5baf-8d60-d64693bb7530",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3901b5c7-4fab-561a-aad6-d35bba012db9",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29bd5822-a95f-55ec-a84e-89d157c08dfc",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ec0937-a071-5ad0-bd5a-c8434e194637",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4535d4f6-ae3c-5807-a362-e4e48a868beb",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.13 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.3.39-tuxcare.13"
    }
  ]
}