{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ae837201-dbea-5369-bcb8-eb5e9024c6d9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.37-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e4403988-bf26-55ee-8616-30b7d557d2b9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61d2c90-a408-5af8-a39a-5404938b0fba",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a9e76da-5519-5f60-8ad7-0cc35d741148",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b49a9b1-ae8b-50ec-92d5-3f3c2d029aa1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b833bf1b-396f-5be7-ba8b-60531f4a45a1",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e28dc89b-86c6-5dc8-9551-18f5bb1980b2",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7d724e-9966-5823-bfb5-a6dd9bfe73f2",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e3f417-a9da-52ed-a4ee-532250cf7c8c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce749c2-b9a6-5a5f-8dc7-d52df237131d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:188902ce-48cd-5fae-b611-638e3f6c3dfb",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23dfe69c-3fdb-513c-8f1b-8abb154edd27",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c20afffe-0b18-5423-83b4-cd467d8fd2cc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0ba3819-ae13-52ea-a68e-1e49c87df59f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c7b1ec0-421f-5275-b5c9-25ffe6807f49",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d366a2b9-c65c-5b81-ac59-e8a20a8aa8c5",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c2528b-3a85-5f66-95d3-c6af3f9c41ae",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e054f2-f965-5496-87ad-53c0b828728c",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41714bd4-193f-5e16-b5a8-b71c04fd21fd",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afeff0a5-bdbd-5196-8f13-53d0f82e645d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff50d2b-340b-5028-9200-bd3a6218b42d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1026ee6-f37c-5902-9834-69326a847de3",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b9ac8f-3ea5-5c03-be07-f5d1b6a3e683",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f9e24bf-02bd-51cc-9d10-9f74dc459845",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe4993a-c8b6-531d-9856-1c1036142aa0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c3dc3b4-e746-53c6-a4f2-3aedcc1e3cbb",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac8530c5-0faa-5883-a3ed-d501c5d282ba",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:debf1789-b081-538b-82a4-ff73d9894b3b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:211270d2-7708-539a-95d9-bfdd9a883131",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.1 of org.springframework:spring-webflux. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e983b91a-5321-5b81-823c-28b19804c4e2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18b5550a-cada-5665-b3bf-6d7e11dc1616",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30416c38-5795-5b2d-92aa-07b7b0d1d7f2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac30da2d-15bc-5929-a623-e7099e7a3490",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:539d09ec-ae32-54b3-a87d-0b172412e1d6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.1"
    }
  ]
}