{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d2de1ec8-97bf-59e2-b603-6a33b50496b3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.27-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6c221fee-0180-529e-a457-2811e94f0650",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86eac54c-4a33-5ac2-a442-abb37f0d020d",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4de4e95f-4d58-594b-9a80-41b2033698bb",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0287a43f-1cd7-5f88-b7f5-20dee9999776",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b61a06b-b895-5907-bdbe-951658d48b37",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c168493-de9b-5725-8bdb-1e4ffd4dd2eb",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b59c7939-d37d-5517-95ad-a8a0cfd3fbca",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:055b98a4-380e-56e7-bed2-8ad89bdc23c6",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df4505c9-c017-5c87-8e0b-6f11a175859b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6580fa17-5046-5e08-af68-0f8ca9ccf791",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dafbb71-74c6-5cbe-9d15-5587fe35c9c7",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df59a98a-88d5-5f5e-bd7b-d7cde2699c1d",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.27-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2483cfc8-7d0f-545c-a939-9b45c7bb4cce",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbf0499b-b97b-58fd-9b75-6d1a0f0868f2",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945c40ef-2b81-5220-a839-4f5ebbcb0686",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc4b7cbd-12b5-58b6-beaf-82452184c7f2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200da691-572f-5076-ba29-3014343ab7a8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3a14ac-8a8a-5e59-ab70-74b01b91a903",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87e95240-440d-5157-8465-46d7551ae243",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:362c59cb-d685-5384-a12d-a36bb1d17cd8",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:490d5bc0-9a9c-5115-b8d3-cf962ba59000",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d14b933-ce2d-5d45-9c02-4e54c4b8a32d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c22c51a-c040-5900-ba13-c3adc2534505",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a51968b8-b8a7-5d65-b758-6201c71923c4",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53a25575-0cd7-5827-81e2-13824c007fdc",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6bcb2c-3208-5596-a083-395e7744b303",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27b4978-b7f8-52e3-a7ff-1d7cbb150da9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c67f61f-0a84-5fa6-b5f3-ef5cf6486215",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:982e56a0-e173-5209-9048-552d1d5de0a6",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7f27b1d-bf31-53a3-92da-48555f4ea22b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.2 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41847. The upstream commit 07ba95739bf4451742e4ee6b4d4b2d0ee5f701bf is present in the current branch, and source code inspection confirms the vulnerability has been patched."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37925d32-608e-5939-b9c6-0a344442ab1e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:558ce2b3-7736-5555-8a04-e9d358b3a3fb",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06a531b-626b-5175-b5cf-64a565a7f82e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:962c7406-c253-5c6c-88a3-48a4808512b4",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92805991-88b1-512a-bae6-1f14c3b39a52",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad03f42-6264-5be7-a617-e430f9a91f66",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86f9d8dc-6e44-5ffc-a501-03f683133715",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.2"
    }
  ]
}