{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5feecf29-4889-5949-9b7c-ca53dfe2efdb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.39-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:66b8cf45-c3a2-5d1b-8546-269a094135bf",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b5051fd-e150-5a22-91fb-d8ed25ce76ae",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.8 of org.springframework:spring-webflux. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0956c21-5979-5d56-b12f-3fe5da89df0d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d6223bb-aae8-5f2d-8148-913e550b834b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e31b86c2-7f34-52c6-9bde-87abde597d41",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d83ff52-2552-5b16-83a0-5518b00baab6",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dd8fe85-78c8-58a2-8365-010776e0df77",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d069b9c-fcdc-5d7e-bde8-567e8258abba",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.39-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d18cf34a-5896-5aff-aa3d-303bd051abd7",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cca79c8-62ee-5748-bfdc-04a44ea69523",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4155ab3-135b-527c-bd75-de671cb01741",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d300839-ad46-57c0-908c-a4724036cb67",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3391ea57-4be0-576b-9ad1-666e3df3fc2f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:570b7989-25ee-5aa5-a33b-2e564010d4eb",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1a3f07-dd6c-5908-a8c0-cba795bd6fe7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c2d374-4099-54f1-ab30-8138ae7b6299",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c4ec64-28ec-5b44-b908-af7af0b4c666",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39bb1e11-2bde-5eb2-894f-9ad14d18c896",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c33bc5f6-1105-5890-bfb0-1cabef7bf52f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.8 of org.springframework:spring-webflux. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e17e95f-c6d8-53ca-a318-8ee12c7e7d47",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:273cb196-8bea-5513-843a-a800099cccec",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2316d84a-6524-55ef-8c87-42d12bb32830",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:403f5a31-49f4-5c8d-b373-04ff583da203",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13592253-ff19-5b10-b534-f40189ec0446",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a2c81e-d53a-5d4a-a94a-2f826bb4fe4a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f90d7f6-a92e-59d9-8ca3-28ae451495da",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535cf2e3-71ae-5ee1-8600-5971fd3da108",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28088af1-8392-5e54-8ad6-2551523896ab",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f82484f-8e4b-5382-948d-93baa61aedc6",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:706f3fdc-ee0f-5ab3-a0a5-8f2d4ad43241",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb7f473-c4f1-5051-81e2-2dbf47d4c44b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46c762c4-39fb-5c40-adc8-14f8c947a6f6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2705329d-a19a-5203-becb-b91c55cac4ba",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.8"
    }
  ]
}