{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://openvex.dev/docs/public/vex-f7abab586170e7e58d89c206b9179d9aaac1748189d3386d0541ffdf734095a4",
  "author": "minimus",
  "timestamp": "2026-09-25T18:24:57.228848682Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-23p3-qw4q-3336",
        "aliases": [
          "CVE-2026-4438"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3366-j6vj-j7p2",
        "aliases": [
          "CVE-2026-18374"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-3366-j6vj-j7p2",
        "aliases": [
          "CVE-2026-18374"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-3366-j6vj-j7p2",
        "aliases": [
          "CVE-2026-18374"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-3729-6w87-2929",
        "aliases": [
          "CVE-2025-60876"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.38.0-r2"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-3jx9-w69q-v5j9",
        "aliases": [
          "CVE-2026-0861"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4c5m-2vf7-4mrr",
        "aliases": [
          "CVE-2026-77117"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-4c5m-2vf7-4mrr",
        "aliases": [
          "CVE-2026-77117"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-4c5m-2vf7-4mrr",
        "aliases": [
          "CVE-2026-77117"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hff-6j5q-cp3r",
        "aliases": [
          "CVE-2025-0395"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hjr-3rw9-p262",
        "aliases": [
          "CVE-2019-1010025"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4hx7-r8fj-4v45",
        "aliases": [
          "CVE-2026-5928"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4mwp-32g3-4x3m",
        "aliases": [
          "CVE-2026-5358"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            },
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            },
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present"
    },
    {
      "vulnerability": {
        "name": "MINI-4xxf-44hj-m8hg",
        "aliases": [
          "CVE-2026-6791"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4xxf-44hj-m8hg",
        "aliases": [
          "CVE-2026-6791"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-4xxf-44hj-m8hg",
        "aliases": [
          "CVE-2026-6791"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-5699-2qf6-m8cp",
        "aliases": [
          "CVE-2026-5435"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-7xq4-37v3-672q",
        "aliases": [
          "CVE-2025-46394"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.38.0-r2"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8fq4-p7r9-vcm5",
        "aliases": [
          "CVE-2010-4756"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE in glibc is not considered a vulnerability by most distributions. Glibc implements glob according to POSIX standards, which do not guarantee memory safety. Network facing services should sanitize the inputs to glob, or configure resource limits."
    },
    {
      "vulnerability": {
        "name": "MINI-8jj9-cwcg-wpqc",
        "aliases": [
          "CVE-2026-6368"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8jj9-cwcg-wpqc",
        "aliases": [
          "CVE-2026-6368"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8jj9-cwcg-wpqc",
        "aliases": [
          "CVE-2026-6368"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-8qf7-3jq4-43w3",
        "aliases": [
          "CVE-2025-5702"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-92r7-fhp5-qxf7",
        "aliases": [
          "CVE-2026-89092"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-92r7-fhp5-qxf7",
        "aliases": [
          "CVE-2026-89092"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-92r7-fhp5-qxf7",
        "aliases": [
          "CVE-2026-89092"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9482-2jh4-39pv",
        "aliases": [
          "CVE-2026-6238"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9w5m-f95v-57hf",
        "aliases": [
          "CVE-2024-58251"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.38.0-r2"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-9x7c-882f-gc36",
        "aliases": [
          "CVE-2019-1010022"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-cmmm-vp98-cjhp",
        "aliases": [
          "CVE-2026-5450"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-f3hf-m5x8-f8fv",
        "aliases": [
          "CVE-2026-38753"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.38.0-r2"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-g3rw-7j9g-j8h5",
        "aliases": [
          "CVE-2026-80489"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-g3rw-7j9g-j8h5",
        "aliases": [
          "CVE-2026-80489"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-g3rw-7j9g-j8h5",
        "aliases": [
          "CVE-2026-80489"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-ggqv-3w5g-76qx",
        "aliases": [
          "CVE-2026-4437"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-jmmw-4597-rmjp",
        "aliases": [
          "CVE-2019-1010023"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-p36m-q8qm-xfm3",
        "aliases": [
          "CVE-2026-8674"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-p36m-q8qm-xfm3",
        "aliases": [
          "CVE-2026-8674"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-p36m-q8qm-xfm3",
        "aliases": [
          "CVE-2026-8674"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-phc3-7qpg-76g2",
        "aliases": [
          "CVE-2025-15281"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-pr9c-2v5q-34m2",
        "aliases": [
          "CVE-2025-5745"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "component_not_present",
      "impact_statement": "The CVE is specific to PowerPC environments and it does not affect Minimus packages."
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-r5x8-hhfx-4867",
        "aliases": [
          "CVE-2019-1010024"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "The CVE is disputed and the upstream project has determined it does not pose a risk."
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rgw6-m9rq-wr8j",
        "aliases": [
          "CVE-2026-0915"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-rpf9-4p9f-qx57",
        "aliases": [
          "CVE-2025-8058"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-v6x9-cc26-3cpm",
        "aliases": [
          "CVE-2026-19499"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-v6x9-cc26-3cpm",
        "aliases": [
          "CVE-2026-19499"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-v6x9-cc26-3cpm",
        "aliases": [
          "CVE-2026-19499"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-vv9p-q45w-3qm8",
        "aliases": [
          "CVE-2026-4046"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-w98q-8p27-cqq8",
        "aliases": [
          "CVE-2026-38754"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.38.0-r2"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-xff6-pcp2-px3x",
        "aliases": [
          "CVE-2026-38755"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/busybox@1.38.0-r2"
            }
          ]
        }
      ],
      "status": "fixed"
    },
    {
      "vulnerability": {
        "name": "MINI-xx2x-q995-7989",
        "aliases": [
          "CVE-2026-19542"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/ld-linux@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-xx2x-q995-7989",
        "aliases": [
          "CVE-2026-19542"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc-locale-posix@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    },
    {
      "vulnerability": {
        "name": "MINI-xx2x-q995-7989",
        "aliases": [
          "CVE-2026-19542"
        ]
      },
      "products": [
        {
          "@id": "pkg:oci/opentelemetry-java-instrumentation",
          "hashes": {
            "sha-256": "sha256:39e4b04760e84fc54ab6ca21c8f415d19f0790bdce3f9eea5d71fb9a65d4aff1"
          },
          "subcomponents": [
            {
              "@id": "pkg:apk/minimos/glibc@2.44-r0"
            }
          ]
        }
      ],
      "status": "under_investigation"
    }
  ]
}