{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c19cf119-112f-5f9d-b609-b2484043fdb0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5",
      "version": "6.0.12-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-34053",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8b772002-f4d7-5969-8cc0-e3ba8714c039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:76cf0621-a9ee-5a77-8eb4-fc06fdfed6a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:91d99ca7-1b10-5e3d-abbe-1226ec233e77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:97d1938c-bdca-5b70-a2e3-64dc97176976",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5edf00c4-aece-5a26-848e-8a3ca0590490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:edf8dbd2-02c0-517f-a8cf-66473ca7accc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e8008942-571e-5b7f-9526-242dbd3f9834",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:17692ec4-2242-5116-b2d8-1994606fd155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d620f02f-70d4-51c2-9b09-f7213e405b9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2d9a200f-7b99-54dd-b2fb-f89f2e49b427",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b7a51abc-058f-5bbe-8459-6e2c60f052df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6c451129-a78d-5d84-bc6e-284408be512e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:afd2e456-a646-5c3a-bcc0-0e7d64ffd220",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6a528519-d8c2-523c-93e6-f90bbddd712a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1ff5a842-8821-5629-9320-1d99d782e653",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dd17c4f9-171d-50a3-a54d-26637d599d68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4e65f3ed-0cfa-56b3-8458-37c40b7da83d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7f55d3ac-e6e6-573e-a69f-865d797ee96c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9bbb45c3-5254-5e90-8aa4-de7cd88197bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ca8d63a6-f481-54ee-9a40-70d345415d02",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41839 does not affect version 6.0.12-tuxcare.5 of org.springframework:spring-webflux. Current version of spring-framework is not affected by CVE-2026-41839 according to the vendor - https://spring.io/security/cve-2026-41839",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:31a0c23d-910f-50fb-9914-cd06ddec64a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ce04458-48b5-55a7-be92-22f3ab7f2aa9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:11111340-5bd0-5f11-ad02-53815afbe747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:62e2c15f-3186-5d55-93a2-b9008c8c71fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:badd7f44-e9e9-564f-88a8-597e34316d58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d891664-a8f0-53c8-9efa-5925fdad4d2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8eb119f1-8ba9-5035-9f4f-69c9d2d4fd87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1bf9d8bf-9284-5c80-959d-acb91be183aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d8bba52e-1cef-50d3-aa1d-126b76d41e58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f864763c-2aed-5ab6-bab7-e3b24b8a6377",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:865eda54-580b-54dd-80bc-d62fc9f109aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:27807b57-32e6-5360-94ef-a54393e8b0d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1276a6d4-01d0-51de-809a-43dd33a63c26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b2356f23-994e-5bff-a3a2-e7b1a8ce27c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c20f5767-8c3f-5c3f-80e7-c7f69cbfea02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:92de26db-b524-5240-80b3-b145880dab98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a3753152-720a-5700-ba6e-7586afc09e6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e9d8c6db-b4ff-58df-a89d-ba706b360cb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9dd721b8-0e1b-5180-a92d-8c5a934ba80a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:af31b01c-5b86-54e8-bcae-4498da4ef392",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6be6431e-9ea2-5f5e-b890-6e21fb657ee0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e136c8f-425c-57a8-bd03-7d2a05610a31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f22e8c0d-72a8-58ad-8ca5-ea0dc1be0aef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a7208da-dfe0-5a93-8705-43ea7d505bc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0dcacf4e-00b6-5b0b-9eb1-ded2b49ef799",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1337a5e1-7000-5607-92b7-d532d9013cec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:29dd3a9a-7fa7-58c1-9300-35893f591070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@6.0.12-tuxcare.5"
    }
  ]
}