{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a1eb6111-56ab-5612-a050-fc5a95395ff9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.31-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d22f873f-455f-5f68-bddd-986fd4738ff2",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e65d46a-b52a-5ba0-87f6-eb49fef5d6dc",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9fad63d-9f87-531e-93f5-bb5e522367c7",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:704bb7ce-a04d-5846-97c8-f468494f1ebb",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7afbe48-afb2-519a-9d66-d0fd17c007d6",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beaeff2b-4e34-54f9-abd1-ca5baf7cdd5d",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afced3ad-1893-5ed2-abe5-ad58b002b161",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a7c9c9-70fc-56db-885f-162ff68ba937",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:573fe8a7-571e-5b7d-a724-018c96350da0",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df3d529-7258-5e98-9b12-b956e0b15019",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3fdecf1-a5a1-5c7d-809d-a7743d7a159c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d887bdfe-34e3-5aaf-b143-9760a49db9a6",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.31-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543acdb5-ae41-5420-8516-f1251aae53bd",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1286b488-2a44-5eac-b786-c2fde9d7162f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd3c26d2-b5d1-5df7-a302-c2d17b626fde",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cfe9ec1-bd4b-58ab-9579-7d7cfddebe2f",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d937d8-2411-53c2-b2f2-aec96b15ac9e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40f837f1-3f8c-58f9-b9c0-aca6624d6f73",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:893dd045-a437-5966-8aa1-82fed6251173",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a952594c-f1d9-53ff-9b6c-f9d8ccdceedf",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68b01167-42e1-58c2-b206-6fe767c27e55",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddf00b69-bd52-5f82-9166-284c54ee6295",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3dcbe51-603f-5e21-a229-86d1f2553b6e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.7 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:565df036-313a-566f-b9da-b84b9fb1a8de",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebf314ea-dfd2-5574-9fbb-8503a1d4d97d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53ae1224-ff97-5250-9408-1c86797f730d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51367601-15b8-5c36-b654-9fb9b68c0955",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca00f33a-20f2-53d7-b233-afc45f21b49d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef0a902d-3239-5c0b-a272-d77a84d8b771",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14ca4793-69c9-58de-b844-9c4f29952d29",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f9cfd06-9f67-5595-b700-260d90b28a2e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:827c344c-8864-5a8e-a977-9efa9ce5af74",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53c808db-272a-5dcd-8214-d36ad9f7be36",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:182a3c19-5eb8-59da-9444-1b9cc0dc9a84",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f198f961-2b38-537b-bf72-9ffb86ba0ac2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5033a64f-0cc3-5a7a-b05a-cee647a3f154",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:865b0b74-b88b-5d9d-9c5a-f60addfc7bc1",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.7"
    }
  ]
}