{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:29145c79-5831-5d31-8bac-1de289bc9711",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "6.1.21-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4bbd1624-bcb7-54f9-8fe0-d4aa60c15876",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc8c3d72-a138-5a40-9863-0232c3a62789",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530e58dd-7b72-554a-9d6e-e61f15b6bf2d",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:929696be-4b68-5983-b986-5d20e598968d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7851c2b5-3f1d-5e51-9a80-8a924fe052da",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3ec4c7d-903b-5d50-96fa-604fb62b66ef",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea87cf88-1b2d-589f-be85-ed88461d541e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8488712-0d87-5079-bab6-6176d43419fc",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86a2847d-08c8-5ab5-8442-4ca12dfd1eb4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eedcdb23-cf06-55ed-8340-b17110c037af",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a7f8eeb-6175-5bb9-8c4c-e54eef58e1cd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b3239d-2ba1-5d9c-817a-daca4152fca1",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.4 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edb953b3-52fb-5a5d-9dec-42e81faf7535",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e92bd1-a96a-58ea-be35-9848644690cd",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e6742b6-9f59-55a0-9364-d8b9912f570f",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71e315b3-c94f-5215-ba59-6c2496c5be83",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf88024-c7f5-58ac-ba13-b34768be8e3d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efd5909e-d805-5910-bf59-c4532772c783",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b240e6b-650a-54ae-9a61-3ae201a97731",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f3b7f3-2f99-5d31-9cc6-cbd7f75b6947",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52fcabbc-aa95-5ee9-a6af-aa8a08af34e8",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eb09c82-be56-5dbe-83bb-bf7c69ec9daa",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31b41d77-7a2a-53c8-9909-630979e37a85",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d93411-b16c-5c1c-bb45-44f6d1deb680",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.21-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@6.1.21-tuxcare.4"
    }
  ]
}