{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1a4429d2-77de-514f-8444-f2bd8ca7d740",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5",
      "version": "5.2.0.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0e549aaa-49c2-5e8b-a5da-e656cacd5377",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1c0ca60d-563e-520c-8ae6-e465ceca77f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:465a2555-affb-5f93-8af5-0c0be0c9258a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c99ff494-d13b-519f-926c-31e9434b90d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a32c712c-4bef-5894-8500-9ebad6e0d92a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6ed19db9-2c7b-591f-be1c-89d586e4003e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:462c8651-dc01-5f12-b93f-34843090780f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ba4f780b-eaef-5326-ba96-1135c95fa8bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fdde62b2-6379-58af-bcc5-9147869a65f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f3423caf-1ffd-5218-95cc-4318fb7af507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4945527a-ff97-51d8-ada5-da8a452e5ec0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d126e583-91a5-532c-83a5-7d7703afe35a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:070b1471-c4e7-51b1-8bcf-0ebc38b97a86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0d84b97c-fd76-56a5-8cf4-e872d6df640d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9c8aa8c0-1c79-5081-83c3-e4e661feb38c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:52e9b639-4544-5d15-99d9-ca579edf514e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:24f5aded-030d-517b-b890-b831ab632afe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8c8ad62a-5f2c-5ae5-aa34-a51c3877048d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ecd9c32-4b44-5dec-9293-aee1a74c4361",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webflux 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fe0f5993-e465-5d6f-9013-d05da49d7b84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:84d1c866-8273-59a8-881d-418dd375482c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4e5af9ac-591e-59e9-91c9-7a2b4ec03269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bf25167c-a45b-5b68-a9f0-d230d1555378",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d0afb98b-6e4c-57cd-923c-d37c19eadf1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:88fa1f9a-e6fa-588c-8b61-435ba4f6f0a4",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-webflux 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bfc60dd0-3f21-5778-a277-860604e55ebb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2f165653-b873-5e37-9026-9ec8eba3476f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bdb81ccc-6ed0-501a-8e24-5577ab3d3e67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4c52f3d4-bf8e-586b-9863-20d2ecf2078b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:47d20754-9c17-519e-bd82-23ec31ed10de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:41da32af-c0f4-5239-bcae-1c44bfc7e14c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2d152a60-a9ac-58c5-b377-59404f7cdb73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dfeac15e-d9f9-5a0f-a3b9-8a659e2f42a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c0dbf610-857e-5877-9202-c2db9ac4a0b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2314f9d8-5227-5158-862f-937db242ebce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2ca2359c-9bc3-51ef-8596-8e9d05971002",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0bb6224b-b5da-5c19-9f15-7d8ec6e8e25d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5b062879-1709-552a-9e26-e4b19cd5aee1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b6f3ae06-2dde-506a-a816-3075850f799f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:74b579b6-9d34-5af2-8347-6f8ec4099a44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:95ae5468-8391-5622-8cca-4fbbca59111c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9f56f65b-e99c-58d8-81bb-27321f500775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ca0c820-4c62-5c72-b45e-40e9b6f33f22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28a48ae6-4dbe-521d-ae65-dd587b1eaf63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:45ab6383-eeed-50b8-a21f-331032d8c5aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1773dbe1-444a-5349-ae47-c71f2835b5ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:90ec2664-73cc-5c56-9426-a291cfc83b67",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e7c3d884-fa23-5574-8cde-9b799915c2e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a36f17eb-b858-5058-aa0c-276371fa344e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:01648ca7-ffef-5fd3-aa2f-d5f5f104c448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:34d1fbad-e563-5f9c-a5a6-d34445903909",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dc459243-40a0-594a-accf-4bf2e3cb7077",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:48a95882-7653-523f-987b-04453791f190",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bef8d69b-1870-544f-8b93-17024b925194",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:95fb7948-f0fb-5839-a3fa-777c3a1ba502",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2cd1c143-b582-5796-9fd2-36034233d525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:21ae3aa5-31ed-5034-b390-e78ed0cb8b46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7a65f52b-05bb-5df1-98ec-f282dfceb583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:36732e8b-379b-562c-9adc-42fccb56197b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a2711a03-6fab-56a4-982a-0e2cad3a0be4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.5"
    }
  ]
}