{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:12fa15d5-e86c-5465-9b55-646cc20bde26",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2",
      "version": "5.2.11.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:953f2447-6976-57ab-a1d6-1889b238b906",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:259891d7-455b-5c40-8004-c4e879782252",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9a9e1f6a-46e8-5806-9008-ff4feb528aa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1aab5b73-c1c8-5d99-a542-14e276700055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:53ee9e82-a965-52f9-8157-2697ce428f80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:22626824-7c3a-532d-a655-2b96cb8975f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f15e15d-aafa-5823-89db-e7ab824d4898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:346afdcb-2e4b-5c2b-aaf8-4a27aa2b9dcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8e211709-5a43-5856-886d-f2e3812914b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f211e458-47a0-599d-95a2-c7ad9d348f11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:34df5711-0e3f-55a5-84bd-d4c11634ec29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd5c9ce9-8cef-589e-8ab5-0c716d46bb04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5d2ca3aa-264f-5e3f-9696-2661b886a8e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:749b1f80-dd08-5e44-a98c-fbf8c82bedb7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:800958d5-159a-512c-ae6a-e73b281def16",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a5152608-e4b6-5b14-b8ef-9d0f4703fbf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:926882a1-0337-5432-8808-4c713070dcd7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e1c1c0a3-b50a-5485-b982-94fdb824aa6c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:23f3bd86-f632-5475-b15c-edaa7122c07a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:496e4e0f-a613-5a7c-b52a-e0c11972aea8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:02af0cea-ba52-5b2d-98ea-a8f43d2ae3c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e0d6f49c-1fa5-5c73-8ea2-f95900cbee8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ebf9040a-83fe-5ab7-b712-3111ce5a852e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fc37f4b0-aab7-50cf-95b3-356c58075d47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:be758325-ca2c-5205-9ef4-5500ef9117ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc88b0cc-51dd-51f3-be6f-8c21f30b4dda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:56aea472-a9cf-534a-8246-8ac61be16bf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0a1e12f-b4a4-501d-932e-bd68e60f0d99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f27c69ed-b1a7-5332-82d9-9ea4d213a63b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c61b051c-6ba6-598b-84e2-b2d6257568df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8500da09-49af-5532-9d52-906282ff8c39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ba84950a-ec5f-5ed5-a834-f83f4047a7e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ae18e0b7-2e9f-5d56-bf43-924bad601510",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2be866a8-da9b-50ac-b895-3c00b2fd5605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5adf7305-66d2-5762-80cc-feeb1febedea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f4c7a32f-8484-59b5-a497-36805a5f7016",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d2ca52c4-5040-58d8-973b-f7cded16f09d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:482d8055-2bfa-54dd-a65d-432d491ea7d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a96487cd-d41a-5449-bc2f-adf959056a9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:01e4e5d7-6d65-5436-ba1d-e5a6139ddffc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e573d88a-8a3a-5263-8261-b336f885628e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:82436f95-e600-5d8b-9c5e-a47f092f1367",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dffd3278-d96e-5962-9ae0-80849574dd21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c2f8e2eb-8ea6-5baa-a595-70f2c02f4b9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:27a7bccf-655d-55a6-b5dc-b58b5841a68f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f0ac8633-226c-53b2-804e-c4d8a01a9733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ee3f4b2-74f4-5b3b-96bf-a1a9743df5c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f37ccdab-56cc-5683-9586-f62101101184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:07d79ab4-a012-5840-adb8-53b261990b9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5c36d406-1f29-57e7-bb27-2993e19959fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:92945e9a-5d70-5213-9a63-f9a215c16e0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:28fe0c6e-e33a-5298-a91e-12354c9b8d8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:109732b1-0ae1-54c3-8b86-8a53030ced8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ebc80c56-a93b-5b4f-aa70-a182cb1e8a3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8892b871-e924-57dc-aad0-4f4f46c6aaad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a9ea29c7-aa43-5632-8e20-7191909df54d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9512863c-c543-579f-9c6e-9c141568586c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:acd42b69-ced4-5082-bfc7-3ec178fc63cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.11.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.2.11.RELEASE-tuxcare.2"
    }
  ]
}