{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:06f1fd54-6a4f-5dbc-a175-c8c0e25d4369",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-instrument",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2",
      "version": "5.2.11.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:69a24216-d91a-5c88-bb7a-3a6d794aa6ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:968586d3-efda-5bec-a563-a45ee2696608",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:44c683bb-0bab-5dcc-bcfe-a63d4beeeb3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e9430586-ba99-53e8-bade-c282ae1f9659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2794ea3f-78ed-524d-8b09-7ecea400943c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2cadef2d-4a66-5f56-8000-9de9be45645d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60f3f7de-f243-5695-9dc4-df3997611691",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:939cb232-67f9-526b-8628-e39156f00588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:453bceeb-b2bd-551b-a89e-e8103ab84466",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eea898a3-e81b-5e00-8e99-f0b9cb0c4fa5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9abb057b-68a4-5d46-9d12-7f7b617c899a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:18de82c0-b889-508c-8efe-066f67093a1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84e1be7d-a60d-573a-ad37-e3997de583a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5043ba33-b4e7-5c55-b21e-e271ffc5bb3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ac49e936-bd29-58aa-9b89-8e665380142b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e55e55d8-77a0-5376-a267-fd732e4215fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4317d832-77d9-5547-a4be-719306ddccfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd3d7764-8794-55a3-b5f1-0b4179aab451",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ae191fa-cbfb-58c4-847c-9dfb2f9b6d35",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e582b401-569d-5a4d-b88b-6607beef9606",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6b2f3beb-f687-512f-a6b8-3e965cebe746",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cda80888-4e44-5fd6-b1af-df685c67e8e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e199ddfe-5228-5b7c-8dad-7fd707c6985d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74ad34db-8c1d-5c7f-af46-6975df8ea31d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a1b1cbae-6ae3-511f-8abd-0e805ee4dcd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2ec6ef7a-f04b-5d21-b2cf-a42f8c35119c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e41f1b2-ff23-504d-9e39-efd54933eaf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:52e32792-7eff-5bad-97e6-26951bfac199",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:04be7f58-f588-5d7d-8d4a-7423c5be9ed3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a99e1577-7b39-5625-8fb3-aa986e237268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c78c1621-2c04-5322-9995-cb1cab0db69a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6a2ef797-81cb-5d44-8bf2-2458a61d10c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2fb0ab62-08ca-5749-a753-a9c55374186d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:914e12d9-494e-565d-b4da-0c656cb9da28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6d67e6f5-d22b-54ef-949a-46c8a4a5d07c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7083bb7-c1e4-511b-aed6-d47a029b0eca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c5ba9d6a-3426-5f65-a832-08319ba6ee67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8db2fc21-1dcf-50a6-9886-87cd284776b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f240f673-aa2a-5537-bd78-0a5c44194c56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff55cefe-f638-5048-9c04-2809d5570702",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2a785d81-383b-506c-9e6e-6cb9b34abb7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8184b0a3-f673-5545-bb41-9a3e66ebed15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0f6dff4-6545-5e03-bbcb-8e0e4c7523ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e6a12074-70eb-55f9-a3ec-3680ed591020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:800da1cc-d23b-5967-9d1f-3bcc46264128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b980cc2-3cd6-5432-9e86-1bd415c2ad32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d04d7daf-c699-557c-b0f8-41cf051300b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:be4e3ca6-c494-5170-ac20-0f759101b248",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f6f4d02b-6c01-51f0-8478-894c0fffd8a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4eb61ab0-162c-583a-b367-957df82d23b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:16c1bfde-c526-54f9-a156-f04aa0e7429f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d0037e0a-a0a8-506c-b795-61dc7207cf77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:16f84cae-d849-5854-98f0-0aa6db488b1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca753c85-711d-52fe-b750-55653e24f7a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d8e9c5f3-da62-52a2-8f63-ae577c616379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:67db94c4-2078-552b-b817-0145eccdaa28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:611be0f1-97b9-5e61-b83c-efd642c8f05d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d196442-2625-5433-a7be-21a30ea8fa10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-instrument."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.2.11.RELEASE-tuxcare.2"
    }
  ]
}