{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f86c6223-e2c6-5f7a-b61f-7649775443f5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument-tomcat",
      "version": "4.2.9.RELEASE-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9c153ad0-b6ad-5ec5-a952-fd6b2b6491df",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f50813a1-1c94-504c-867d-1199e50aed3a",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a0ac0ce-1b85-581f-ac6a-8a213ca26e2e",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b44b381-21fe-5ec7-af41-f8455e77348d",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01dd439-8ef1-5df5-86e4-4126b650a29a",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4e9b86-7df9-5951-adc6-ada469300be3",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eccf52b4-d868-55e8-9cf5-0e989ae0cb97",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6517894-6cf0-56a1-b81e-5088cd41101c",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7239a393-22d5-53b2-a406-67dceaa6f8cb",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97681321-cb63-549a-997b-a5e1384932d6",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b78ea3ed-ffd1-5732-9c46-b9c0637aed75",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4780cf20-4d11-5e45-b096-35d8fead2f38",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be11a30-34c6-55ae-b74d-e01a3a5980ce",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c479ada4-81ca-56a9-b0a7-5a0abe10856d",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6661cc0f-67a9-5e46-934f-8947c8a35f12",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1fc5969-7d47-5509-b6ce-556f319a3e30",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88acd290-383f-5576-b2b8-1e619c9b2bfa",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abec6c31-f342-536f-a4aa-9833e60d7651",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2d1a104-3bd5-59f9-99f3-fabefe332cb4",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:061796f2-d7ff-5bff-9e05-5e5a300028eb",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6240e907-f309-56e6-b432-ea6f6cd46eec",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ccebe7c-e382-5262-96ed-7303ce78a3c5",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af65d02f-b5a8-5aa7-9c36-09d1272e319d",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b68ee744-ca8c-5d28-91fa-5db6be8ec551",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005bb3ef-03bb-5272-86a0-21eb7b5284bf",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d8c50d3-6407-54aa-a4c8-ad751c815245",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944aa974-de59-5b15-aa32-1792a4469eb5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c57561a2-489d-5334-8013-805a39c67a1b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82e20259-ccf2-5e03-8d2c-6f70a18115ca",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c4c0c8-5fcc-59a0-9629-a73fe18a1c6c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a63bd36-bea0-570a-af1a-b5de237ce343",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6a5e63-f707-5b58-b79c-89e0432f123a",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e74113-c797-505f-8195-c5fb762d3e27",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7807ed0f-b04a-57db-9a8f-80832e154b59",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7af2310-08c0-598c-856c-77895e6ca7ba",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9f9c6f-4665-52c9-981a-eb3c8cd91609",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f14abc3-c6b8-5d9d-a837-3889325531df",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67fc3f7-65cc-5e09-9c5c-fe44b12d3f77",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556b0940-b071-5400-8f35-36765c459ba5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53d8e8e5-96c5-5b24-be92-01e9e57a3c1b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:befba368-d700-5d1b-b189-40053c4bd69a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d5327f4-4f26-5f10-94b0-21dfd3c10329",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd15fd9b-d321-5138-8623-99445cfb87ef",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aea314a-0184-50e0-bd11-b30aaf447370",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18e97d5a-46e0-57c0-a1ad-07ab04fd2833",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c098f907-190a-50d1-839f-3f80cc91fdac",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.5 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.2.9.RELEASE-tuxcare.5"
    }
  ]
}