{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5c3f3ba5-b1df-51b9-8aab-4a689e9b7c8c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "6.1.21-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f27065ac-838b-5646-8ee8-0895dd0ad0eb",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af9d8a24-22b5-5fce-ae5d-9d0adc2c85fc",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fd1d66b-ff9c-5ac5-a74c-4cb185b88ef0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:710a8151-022e-5777-acb0-df3ebef39f11",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ca73ac-2647-5413-9647-ff5968c4ea65",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:919c209f-b2bf-5c0e-a542-b1fab2304c17",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51ff15ca-5766-51a2-a513-a7f23f158fbd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c829fa-427e-5093-8b69-05e8c8f8680e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:634e7206-3deb-510c-95ee-ed12c341c1ba",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24fea6be-db5d-570f-a884-353a495abfbd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beec0031-f66f-5bab-b19a-12fbd2bc8393",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1052d93b-de40-5a2f-bb44-99fcdd85e19b",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.7 of org.springframework:spring-instrument. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c6aabae-f3bd-53b5-9e7c-4c2136690b6c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cd39aa7-efc8-55fb-bce4-7d845bed3868",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b226e0-b157-5ed6-a9d0-7a4b4a833767",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5d9ea4e-86e1-52eb-a76e-64390b4e96cb",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6f935f7-d567-5200-9c08-7a5ed1189a7a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9114be8-dd13-5f67-923e-20e7009b774b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7b4ffeb-abf8-534c-a9b4-70683eaa9486",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15b52ff-b9ab-5366-b61c-003b8df974b2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31632886-e41e-57d5-9daf-cddd57892b39",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a07c27f-8739-59ed-af36-59da5d1f8355",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b8bb3a-ab0c-56cb-8d56-165180b515e4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e9198d-e9a6-54ab-9953-526b1f9f00bf",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@6.1.21-tuxcare.7"
    }
  ]
}