{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:50e50b22-fc8b-5939-8595-b8437c1a03f5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.39-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5783a651-39bd-589e-973b-0c970300021f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec51347-ee7b-59ed-938b-afca859d5b1a",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.7 of org.springframework:spring-webflux. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c98be36-cc4b-57b9-ac2b-b7a62bbaa212",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e2a5fe6-2107-5549-ad55-2dc82f877377",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd6a77d-e23a-5d35-95ed-0cb27ac30afa",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:641395cf-9807-5554-80d1-93fa4f7626d6",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a707d878-a4a4-56ac-adb3-a270d95959c4",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f01ffeb-aea6-5b27-ba1c-62746e2fa050",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.39-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa76b6cd-8edb-5a1d-9621-568510101ce0",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d28fd07-0922-54ca-9a1d-42c570b29956",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fd91d7d-d4a8-5b54-a9e0-1416c1c89b3f",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7f65d63-8724-527f-9712-d608bb123a1c",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4bc0558-8c00-5d3b-826e-9bddbe1b74d1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76884e96-a938-5fb5-9286-0b7a7474a411",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3324ee79-7cac-578b-af67-3f025b404e51",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6237b3a4-ea31-5b68-a71a-10da3f547628",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:385174ea-3353-52cc-9c41-9392c8d27e3f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:172a2eb3-9605-5ed1-8d26-183c8645ad2c",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af966814-17ca-5115-b168-45e401dcd8ed",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.7 of org.springframework:spring-webflux. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29efdb30-e2b4-53d0-800d-ddf1de1eba09",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a278c6-37f9-54ba-8680-6958b6bd1d01",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67984f4e-ab83-56e2-8077-d723962ffda6",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4d8a99-2e5a-54e5-938d-d02693a66f30",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a14935-86e9-563c-be2c-eb5e6e10b49c",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b1befb2-de98-5fa1-940b-2dd97e22448a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1d9de6e-f932-51bc-b43f-fe85211eb2d2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4535e83-6da6-5c7c-85cc-1a09cae42c34",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccdcd2ba-52ad-5fe5-97dd-9b999d8e61d2",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9341dfde-1d81-5e8b-8b28-0279f4e3292d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a416813-3b5e-5aca-a325-ff09b2034bfc",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04878d8e-5e99-5ca6-8fa1-78c186608e74",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41f18273-557f-5cb6-8b26-9d3378433a37",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a3894c8-b6b9-5691-9ae8-10069b75fd97",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.7"
    }
  ]
}