{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:75c9a4b1-c851-5008-a3ec-3eab8ac81d55",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "6.1.20-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cedfe514-f910-5b8c-aaa4-f298fd8912fd",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e290a6bb-2c2a-5c31-879f-e3bc3bc62fab",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84915f61-8191-58cc-8fba-e613bf333cda",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5b2ce40-2707-5379-be38-18299d74baa6",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24e26cba-c001-5d80-8e06-bca896820702",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d46675ef-7b8a-5923-8821-36084ac6d83c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e44518c-4555-53e3-9550-119a1dd7b1c7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad61a4f-4198-5c55-8740-68cec6ca70ca",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5e1df13-d6c3-5a4d-bbf5-91c8046c1a54",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95478e1-4e59-52e7-8511-efeb936891ae",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a198a3d9-f904-5f70-b6e4-049a57cd034b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7cc8ce6-ca35-53ae-ba36-e841407532b9",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07971ef0-773f-58a6-a5fd-62b529a93ea2",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.6 of org.springframework:spring-instrument. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f12a282-6089-5f91-8729-bcb782f01470",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9571766e-f27e-5918-bd4b-dcaa396a3fe7",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9da2386d-93ba-50fb-b7f2-d47d9bb97093",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f5c5fb4-e20b-50c2-afd4-9bc9e8b3a851",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72b526ad-458f-5ead-b483-bafe5a0d6a94",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38156ba6-61f3-5713-b9f9-fa1f7fac8058",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00339d61-55ed-53b1-a221-94eee2d343ba",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c579d8a-4f7c-5ac4-bb53-a0132d2441f3",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4ef5331-98fd-5804-a199-d21733ebc504",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a4b0313-bd3e-5a0a-9d4e-df7550ec6a19",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d86dfc26-c9ce-5548-a4bd-f78aee3c3e57",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aaa0145-ac97-59b1-ae6e-cecbe3b561fe",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.6 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@6.1.20-tuxcare.6"
    }
  ]
}