{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ec0f1d5c-5685-5b34-bfe2-7a2f1b947f4f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.37-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:190c78da-4446-53f0-a010-6375acd7d8d9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600b48a3-34f2-5b8c-90c7-b0bb571deec2",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dc809eb-3d17-54eb-93db-98b17c497e01",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d38e6546-afff-574e-abfc-ddece2139197",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a167ba9-ae7e-580b-8c9f-860dd1fa580c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3fa25e1-b44e-5191-836c-0b28fe892713",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6023d97-e577-5796-9cc6-7c05092e7b45",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2f48d89-c64e-5996-b020-9fe12adf1522",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d25fc621-aeeb-5e9b-8421-2aa99d0578ca",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45eb5f89-92b4-5c0a-9cb1-6e7465a82142",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1db96256-e9cb-599d-9122-9d95d7d872e8",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:585f13af-b60f-589d-bbcb-46b6c9a18fa0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b4de4e-403b-52ef-aa25-b4d40418d1d6",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0e0f59-6915-555e-a18b-b1b11b85d833",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38aa4405-ecbd-5f7f-bbfd-c515cd68396e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55a15a5-e198-5bad-b063-332f672a2a2c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6186b817-77a7-5f03-a849-413f0cfdb945",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27f91cfb-1181-5f85-8eea-92fe4bb79126",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c17ecc99-ef4d-568b-9ee8-7ec51add3c76",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.4 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e96032c3-c7b5-54c0-bddd-b1ca9538c670",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53ff7074-7520-5f73-a31d-e25ae4526bd2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a4f7ad-81c5-55c0-be1d-20501af92beb",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a8576f-452e-52f7-baff-7f234d619746",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cf759ac-6039-5a9f-bb71-7792706bef3b",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db58960-1bb9-5a64-bb41-5c67b2cfdbdd",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d6b1da-ce14-5abd-9b0b-9e1564bdaf98",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba76155-e3c3-5f51-a91e-fb50c8426e2d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:988a55ef-1047-5494-a0cc-d1705f7ad552",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.4 of org.springframework:spring-webflux. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b63d3a1-e038-5e30-ba4c-b282e5df0a4d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:187475c9-f0be-5279-8442-f16e042e28be",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90bb5627-5cad-5e12-9176-2326f18a57ff",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcb85fe3-c444-55e6-afc7-3f088fe78df4",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c8921c-50bc-5d25-9ac2-47e5c5b4b350",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.4"
    }
  ]
}