{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:255ce0fd-b932-54da-89b6-f50036f2a508",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-r2dbc",
      "version": "5.3.27-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8747534f-39d9-57a1-b44a-497b713754b4",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e4dc28a-3f9b-5cc0-bdc6-e61b17b14595",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53d5fd5d-65d7-55ed-8419-c80ab98569d2",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a555f2e3-37e0-5a4c-93d4-fa9f40a04a47",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ddbc9e8-8a9c-5504-8560-e1ce5f547d9e",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f994943-d23d-5fe5-997c-5ad27ebee7ae",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b049edf-dee7-5025-b377-35f206cf4b1e",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ef5761-4048-5293-bfb0-42a47ac14ab2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ad9296-3869-5e4a-8c91-b138a1644cd0",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3461f02-3014-50ec-8eee-b59d93b24416",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a461c538-6c94-5419-8eaa-b039556866db",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ca52e9-5267-5034-a484-f240f7182a6b",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-r2dbc 5.3.27-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c125ac-5dd0-5328-ad8c-ce3a1ef54ffc",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170d9928-2a7a-5c24-ae0b-a0cadcb5171c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944dc83b-9036-518c-b929-f1996fa2135e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f20d1076-6da3-57cd-8789-a3514c83f7d6",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a371ed6-4344-5c5e-a4c9-b535d3ee72a1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ece5aba-6284-520a-945f-a5037e846762",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a155aacb-174c-559f-87dc-82d22e10439e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c586ed4-5bd5-5cb8-a0b5-a12b003b31d4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93cd3a16-5d87-5a49-b26b-a31dbefc0db8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bef5ad04-e1ee-503e-84fb-2a13a073871d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09e9427f-830f-58a5-a277-eac133f0dd51",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94171f2c-baf3-545d-9962-b8bea4bc2d7f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bf341d9-8374-557e-a75a-7f8376e0aa6a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5db4524-dc2a-5abe-a208-7f75be433295",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd49b98b-bef2-5cfd-8905-631141eae53a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fe9c145-9c8e-5a58-8e5b-db275df94687",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bb8a116-442d-5b4d-8d57-00ce81908e9a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d5b7a58-d095-5926-8f8d-76ffeff2f63f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78fb70bf-5ad4-5a6b-936a-2b95f55b2e0e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd7762c9-973d-5e7b-8cd3-2c195d58840a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf99b84b-b65b-58a4-9dd2-a2c2f8c2b7ed",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bca834f0-5b94-5609-967a-246597e84ff7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:851f9e72-4043-5af2-a0b2-b9abfef63455",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5d069d-7154-57b5-8276-b97e07c65f54",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7650d45-920c-572f-84e1-a1737f219795",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.4 of org.springframework:spring-r2dbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-r2dbc@5.3.27-tuxcare.4"
    }
  ]
}