{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e17b98cf-849e-5ac6-89c7-313a9c1f966e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-instrument",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1",
      "version": "5.2.7.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81d1bd8e-6475-5660-b9c2-5f03d1be3a4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dce155bc-2677-511f-89e4-2eed7758c21a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a15bc3f6-7816-5e99-b0ba-35cc7c5c1a28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7620d4a6-1860-5c9e-b903-88ac310bb845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ef87c8e-0324-5609-82f1-25c6828277d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12c153b6-c3ee-55a8-9d09-d449a5878b8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b5a383d1-12d1-5d50-a067-a2cb78d5d8cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64fdf677-4903-5bf0-98d0-9c71694a1860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0db1e178-fc85-5f90-add7-36e559c1a635",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc3973a6-3d0f-56e5-a41f-ab5f94e5db6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:981244b0-4d72-5795-b1c6-9cc2489317a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d563c13a-5610-51e0-b7ed-a590945d715c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71d8eeb3-dff0-5ed7-af66-82556356ed33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ea62ea2-3849-5340-b3e4-d9e5f5022539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fc71b188-f5f2-5863-a8a8-36497d699415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49f3f848-9cea-5bdc-97c5-475f3abaa9ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a3493f60-d863-5b0d-b315-4fa182b2401e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe65d7ca-b135-5e12-bafc-c7a8edd32567",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b3d999a-2a72-5249-ac26-56a770bd4c88",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:228e2863-f735-53b7-a7f4-c36a4833f25f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d86a495f-a484-5c79-91ce-a6f8791548a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1adaf97-411e-593b-8e77-ff117a930e0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b67e0fc4-2a75-58a1-b03a-303505208c8c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dea7bb28-f161-53ec-90f4-54053ae18f59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b6415932-d9fa-52bc-9138-3b3d04eabacb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e815c009-907a-5e68-82b7-6942c124ded4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52e9fce4-2966-5a36-826d-6211ccaaf96c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0eb19607-32af-505e-aeb3-aa0eb6b8a520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e46971c-fe2a-57a5-b711-fb8e1043eb85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0050aac-bc5c-5d93-b0f3-690c102be17e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20419953-7538-544c-9ee0-e2d29066321d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45751200-3516-5236-93ed-cdb30ee5ddcd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d3a57a61-90d5-5e21-83be-1c4f0831cc4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:23173295-60cc-559e-aa98-d2c02cefd8e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ce6086d1-e0bc-5c69-9a17-0293510843cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b67c2d32-dbdb-50fe-8eaf-11a32ae61a76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b615629-7133-5aae-be3e-dcbcb151f409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44a87446-e53f-527e-96b3-9ca83843e95e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad61eede-ff07-529e-886d-91dd0c90320e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b0314d6-a233-58d5-b422-1e2cb2420aac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eefb9062-6267-5370-869c-0d88524521ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:99a8f785-6b54-54c7-a7b8-af38a1f0f8d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ea60d50-217a-557b-9692-20dff4b80dbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6dbad0d-9b79-5933-ba19-89fc4f6347e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b1ac1a31-4a8d-568a-988f-0763fd8d3276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b7c66055-d2ad-521c-bb26-ce3292d2f250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53fdc086-227b-5860-a05c-45e55ced7642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:68c7d209-71c1-5297-860f-eb7c40d0bccc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bdad7a20-530d-5b20-b9cd-60680cdced92",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:312548ed-c0c8-54dc-927a-16bb15f72f73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86b6cc5f-3eb1-51c8-931c-98fa5d870c74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d8312ba7-eeeb-51ae-af1e-79b0bcf49d20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b81be7f-31de-5c55-b10c-85d50dce7da9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:086af7c4-9895-5657-b1e3-41f86cee6dc1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82128c70-3408-5f07-b3b4-d52b89fd5bc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72ab1f8b-fb9e-5873-aff0-b4fa41ce7cf9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:23c0a1bd-7bf9-5092-90ea-2a54a7deed52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f3058433-56ad-5b11-b18a-a55aac0ac129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.7.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.2.7.RELEASE-tuxcare.1"
    }
  ]
}