{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cfa084d2-8d2f-501e-aeee-a55bd0406753",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4",
      "version": "6.0.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3a53e903-526e-5aa7-9753-14a420eb9d33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3519b9f8-c678-54e2-b339-b16074990bcd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-34053",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c8b9cfc-6315-5d07-8b2e-36c1a8649261",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b9f6339b-fb8d-5166-9ba5-b02327690af9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65992f6c-ad00-5b0e-9352-386704c842b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7a74a5a5-bee4-57b5-a594-a5da85e4eb2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d7f357e1-d1c8-5fce-a95d-d3cd3f979614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3f971aa2-8763-5ead-9111-5ef0083dfa68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:46aa2b37-4af9-53bf-9186-a66c6d656bcd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:611e69be-39d5-5e83-a85e-e5c2a82e9223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:760703f2-8376-5b59-9c9d-3a804e295d46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5096e614-917d-5641-9076-7c300f27cbbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:93b77986-2297-527c-b432-28dbebf58e92",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c93037f6-ecc2-5073-ab80-92024f07cd66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:09c71aba-c0b4-5384-a95e-e3f74006c306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9cc0ee52-ecae-5f07-8ac8-b4a3c1f6ba9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:325864ee-efea-5e04-9804-0ec3e9e8a5cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:554d691a-b436-548a-884a-b3e3f15e1a98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d2c3a29f-8067-5baf-9936-64d0f89a05c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:494ff580-a470-5eea-9a17-fc120565b3a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:41c0fb50-2bc2-55bd-9e5b-ce215902a10b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c611d371-5611-50d0-bf2b-7ead9f4ead3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d62a44ff-985b-59ba-8711-ca3ad0019b00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d6e47f9f-eb67-5f0e-b5e0-0124d548044c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:42d0b42f-0cf0-5ae9-bfc7-43ce5786722f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5279530d-f596-54c4-b78e-192f900816f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d25e6a00-38ef-5911-b31e-75a512e944c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a494f8ab-bd24-5f72-ad47-31ad3d2fc8bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0106ddd3-34a2-54f4-aeda-ad623de8ffaf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:86fb502d-3aae-5ee6-b51c-b27a401c18e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f1c08587-8286-5f76-8739-0870707a626d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8748749d-b943-5797-9d2b-b7a47f41e57b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:343dd5af-cdb6-5f38-a821-52ff0e2e2f4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:54731c08-ce23-50e2-802a-49b528ec42f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a24dd41f-f523-51df-b867-0cd189b4068f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a5daf0e4-d2c5-510d-bc03-7f046e6c1fb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:89dfdc2e-57b4-5190-8434-754f43fec64f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:31d92eb2-d21d-5a3c-ab1e-7bb7a317f1bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ec71ed09-9773-5cf3-bfe0-ad395c02e26f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7a625af9-ade3-5625-bd73-9fc7f6acec8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bdcd1c62-f632-586c-b86e-2ae8dac4e7d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aea75f2e-d76a-5117-8162-f5ca76f9be79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9568b941-e18f-5655-acdf-ad1e5f968b18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cb2ea85a-0ed0-5333-b63c-0b269f048a10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5904f5fb-4d8e-571a-a57f-09eddb464a39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d8f422ba-3a94-5a4d-8ac5-b8e588b2859d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c8e7085e-c8fb-5661-8121-ce3b083422f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a177f529-56d1-50af-8dc7-f76decc53518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@6.0.0-tuxcare.4"
    }
  ]
}