{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:611b9ccd-3bfb-537d-9076-77ee395d7a21",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1",
      "version": "5.3.6-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:90170691-086e-5464-adb7-7b8c6d5fef2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:efe9d1f7-eb51-5949-bbd7-a4980c16c8f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59d60e90-a1b5-57d5-ab5a-466ccd52c091",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e82cd45-6fc6-5852-855e-333b8cdbae5d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9057d6b-e37d-5d8e-952e-b9ec4272dcb7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:813e6880-7cce-5b24-9cf6-b1c99320d592",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:090af21f-d4f2-5f4c-bf1d-24a15c2f1967",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0717da7d-f786-5222-a258-ed87ae755bb8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f008e08-054e-5864-b165-17cf53d80e88",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0170b95-0ca0-57d4-afaa-18273568252d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:015e66ee-afb7-5d06-82e3-a023aba68ab3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec8b5695-474e-517d-99e1-e364266b1547",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:058bf341-fb29-540f-baab-fc4b9accb969",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e40e1fa-4c62-5043-85d3-520282369894",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94c435e8-9134-5e7f-acb9-03871da22b25",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8e2f823-c19d-5768-9743-a2e6d54f4ee5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d153a71a-be11-55a6-85ae-cea003f4fe89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b50aae0-2cff-5ec7-a31a-23b4cff7a0e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b9924935-0b83-5293-aeba-2b01e25faf1e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c74c231-c95b-5ec8-8c33-fa8a8bd32b90",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.1 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f53719a-dd0e-587a-a947-3a76ed622cc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:812609fc-b2b8-5e48-bcec-1da773af905a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55d14cfc-34af-5f91-9bde-55da80c3014f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e26e09bb-7dd5-52dd-b691-c9824b2a9851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1bdb0467-cb65-5b5b-94e7-b16caeeb7d4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5baa9271-0d16-5163-827b-5f11f199c423",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b5c911d0-cc5e-529a-b7cf-040bb999c40f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f7dd89a-26cf-5b2a-b7e6-db6ebdc0b7d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2628ffde-7df5-58c3-a5fc-e16b3d07fff9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5be4bdd0-5e55-5bfd-a938-1d29b071d39b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4173c483-2e05-51de-8395-6f78065cf700",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1093ab8-4f65-53ae-9141-140468a32cae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7416e2d3-5630-5c91-a682-046e8db2d776",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74ce7052-f9bf-550d-a9fb-d2cf4013b1c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf5eb61b-b76e-5ac8-9c96-394362d9180b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20aa3494-595e-59e9-b6f5-76a5282185ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd12f9cf-227b-57d3-86c8-76431cdfa20c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4cdb5afd-d7b1-557a-bd27-39a9fa0b80ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d6b9276a-bf8c-5eb4-b5f6-c6a2beae8017",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b1b69d8-4639-5b80-9d8e-b040c00550fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d0c7b693-2281-5fc2-b60b-833d455e9ab2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a3a4217-55ca-50fb-ac20-3a58a0a1ed9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:91a67d55-525c-5dbe-94d4-219528f12608",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e93368b9-cb24-50c2-9a79-f782d21b0860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b06e0af-58d9-556b-96a0-34f3776f5dfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8072f5c8-a80d-54f1-8cc1-7e694b61cdb8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b4e6ed2-d69f-5f06-a93f-0d34970f182f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e26011e-76e3-57eb-86cc-40ab8dfd017e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:345d9b69-1198-5733-b2dc-045e7dedde3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18dce243-3c24-59ae-8b80-ed8ca4841360",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae36486f-3a79-5dc2-ac9e-4d009199a529",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dd6fe4ba-033c-5834-b5f4-8ee6fa1d0eec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:08eec602-1cf1-53dc-bcfd-b2a48de94a18",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6bf538d5-cb01-5048-948d-1377a6198145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2e290bf-95d1-53a0-8a3d-59746f672bb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8c0fb12-bf2d-5083-b8d6-db244500ae4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d99c0ca-0481-5599-98a4-5c5513106a84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:917489ba-e79e-5479-8fb9-961f3387d340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d14e253-786f-57f3-a4e3-1227abc38002",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:081805bd-fd9d-58be-bb1a-bbdf9cbf91e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d9d11de-e269-5f40-b7aa-1891a327a1da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.6-tuxcare.1 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.6-tuxcare.1"
    }
  ]
}