{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e745fba8-ea42-56f0-9742-82867e009a6d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument",
      "version": "4.2.9.RELEASE-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7bed9317-58ec-541d-b109-c727f83491ff",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-1000027 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a564bf5-699d-5ca8-b1aa-fbea8e2b9c4c",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39fba4f9-9b79-57b3-9e0a-827f0e2dcf7a",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d08b997-9486-5607-8171-4e489d85b6ba",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b20493d-d830-5a48-9873-882383efb087",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb2277d-f10d-5672-8f51-2cdf4a3df63c",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f52e130-a3f4-57bc-b6c3-80e72fdee48c",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b0d98e-6174-56f6-8175-5f9a3ab2dbbd",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e93a0630-ecbc-524a-b589-23c24474c388",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb63bc4e-9a44-5f1e-9103-41ff285b0e68",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2279f3f-449e-5c41-8656-c99d51827bfe",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6478a2d-5383-58b3-9541-f239e44f10d2",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31aef85c-5c66-5463-990b-1200be1ceb19",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bfbf5dc-fdab-5c9f-80e0-09da69ad9879",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da646a7c-dfca-57a1-b29c-d5310b95eea1",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f9a324-3d4c-5c73-9e15-3f48eec376a1",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f5a65f9-bbdd-52bb-83d1-f21358607817",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:429e84f4-b715-5e4b-87be-c072180c17e3",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c96eb28-e106-5a04-8c54-b1570a495123",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0052f9e-4f98-55a5-bc95-4a0f094454d5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d21052a-2c1a-5270-a2d9-1b96c93ac1f5",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aff98e8-3696-5f31-b4e7-02d034de85ad",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aede643-caa8-5f21-b0f4-5d01a495a73f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d043d585-3abe-5657-a6fe-b6130311b077",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df04d536-0575-55ac-a567-bd94c979e934",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c21df5f9-02b5-53c8-9da9-8befa4f085dc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14f58e2c-fdef-5653-b404-70d7d2c5a4aa",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95112556-a7c8-5bef-90be-ce1a06d35efb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0770071d-4d68-5344-bb9d-41413526cc1d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd228ce6-a148-5dfc-88f7-96e12ab99ed8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b436065f-411b-55a9-90a8-45e30dcf100e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f22e82-09e1-5876-9a78-0625470b617e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a7285a4-5b38-5519-9f39-dd9b257621a6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ef7de58-cc21-59c7-82aa-f3c6b8f48705",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fd7fceb-bdca-58c2-82af-0d7688165170",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4bc9342-8429-5099-a40e-247cebb6883d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80effad4-b53f-5b06-a49b-b9489a589797",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe5216ae-18d6-5b81-a422-8aea0d55fa94",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a93272a3-3ee6-5224-bdef-939620f25968",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf8839af-ea72-54b1-b6fc-f9ed7cde925a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dd97e7d-8358-5e90-89d6-75d76930c08b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ccc244c-7d17-5eab-a1d0-ee46063aa32d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17dcefd7-d131-5b2e-9e36-89105c326931",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4900d892-c427-5131-b9e5-1fb1e9756df6",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e22aa95-cc11-572f-b5a6-5f77e086e544",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c96fc94-ecec-56cf-8b7f-3238e96bdc6b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.7 of org.springframework:spring-instrument."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@4.2.9.RELEASE-tuxcare.7"
    }
  ]
}