{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bb22d491-06de-52c6-ab03-e01ff8e5a520",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1",
      "version": "5.3.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a225963-4364-5573-b79a-0897979bebe6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:761b03a4-6b83-5a02-9971-1c8adc0f94b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da533277-a513-595e-9168-2909e6eda3a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f43707b2-285e-5fc7-8e3d-de8f4c8f276e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d113f56f-b088-5932-a0e9-8a8a435f151a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:60240131-3ed4-5eb8-9803-459dd68c6b14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:30974180-5860-5054-b46f-1db424cac84a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5246906c-85b9-5830-9bdc-3a2527ab00fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b67c1812-70e4-5269-a93d-4a03d163820d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b32d8281-cb4d-5472-b6ae-4ffa45649626",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e765ebce-fe9c-55e3-b1ed-2ed22d64cfdf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3a26b10f-9c84-507e-aacd-ca55318dfa37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bd9b63a6-5b2b-5adf-b30a-7ed1ebd60b7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be8a1d52-6c30-5f4b-b500-7a17d2f96127",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2d21f57-f4e7-51ae-844c-8fba93456945",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ecab29ba-fa4a-54a8-9192-0a3dfd60482d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a180b16-2e2a-5469-b796-f5df7af4a5f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5cee81ca-20b0-5aec-92e0-d91c553d1db9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cee7547a-bfa4-5875-862e-3e41504d67c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a4c42c7-cd39-5a3e-aab0-ae875fe18382",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.3-tuxcare.1 of org.springframework:spring-webflux. not_affected \u2014 Version 5.3.3 is not affected by CVE-2024-38820. The vulnerability addresses locale-dependent toLowerCase() in DataBinder's disallowedFields validation (introduced by CVE-2022-22968 fix). Version 5.3.3 predates CVE-2022-22968 and uses case-sensitive field matching without any toLowerCase() operations in DataBinder. The vulnerable code pattern (locale-dependent case conversion in security-critic...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53e2b314-3057-5aa3-a5d4-700f40dfb6ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a132d468-afb1-5152-bd29-cd655f7bf552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:adafa4ee-44d0-540f-aa09-b84ffed93dc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c237c33e-10c1-5f40-9467-5fee9fe073b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:366d2481-8019-5b3d-afb4-7bddd8b77687",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0bf78030-e0a3-5adb-9ef6-be4b1c55bca1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9e51f76-078f-559e-b13f-04dccbc3ccef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55e9fd17-9af8-550c-b396-4a4bee57fd31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d4ae7d1-32e8-5485-b1f0-93f76f9fd904",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f97fbe49-dd0f-5903-a7e8-de2c79ea581e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a4de9d8-d328-52f6-9d0b-961e69f39fa0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d9cf39b-3ebd-5def-b9f8-84658490da64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3828cbda-ede1-5a3c-8a25-37656ca65942",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4161d0a-2c20-5642-b278-f5cae62fcf8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7aaad671-d635-562a-980e-46182761cc67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01b80d42-4c7a-5c4b-ba94-b291423088cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2afe4a3f-1b41-5336-ac5a-0b1d2569f338",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:574cbbb7-9874-5350-89ed-b0d82904caf2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e3dae2ce-267b-52ca-87e2-32cbb7b65394",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:337c7135-acf1-5ba2-8580-85429f441d3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5cbe193-76a3-5c8f-a8b4-b8701b7db2bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53be93f8-ff0f-5737-888b-7403c812fe42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:938d1dc6-824e-5aef-a663-2fec4e976a22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:01c1a787-b0ad-51c4-bba3-7681b3cbcf60",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:057c9966-858a-582e-8a7a-8b4f57eedc03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3f11a02f-6769-5545-ba37-bb9a346293bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:838ef39f-3cc9-5113-a794-791408161dd8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:83133fab-e52c-5eff-a03a-d4d3a73e4237",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:83a73c95-f558-52a5-a264-4ced046b3efe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a806206e-f28b-5a3c-a777-10da991eff7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87e1d052-c834-5505-a564-ca067c972bb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:93ccc587-2b3e-53a5-9cfb-dbd631dc3b06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ec225e7-c9eb-5dd0-8322-386363d7648b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:95d5d844-8036-5dc2-b7e5-f234b530c8bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d980878-aa72-5f00-b53b-45ce2dffb132",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b14e1dc1-efeb-5d4b-9f0e-8c3fb15f773d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5649f079-6bdc-5323-b34c-0f2ea6a7ae45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b6ed440f-6d9c-528a-87b6-4f2ecaff411c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:356f0fcd-5a85-523c-87e6-1b7f5f70d8ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fdaa85e-46e2-5531-97c3-f1a7dd3753ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9f6727c-97a2-5755-b9d3-7b67c6c352a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.3-tuxcare.1 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.3-tuxcare.1"
    }
  ]
}