{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f33fb140-a154-5c67-bef8-e61434eb2277",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6",
      "version": "5.1.20.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b8afdba8-2504-5f7d-87b3-7c4a9ceff313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01ea296a-7667-5fb9-a36c-8816859ded87",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:77f5d3fd-8116-50ad-b804-5cecfbe10a52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3f8eafbd-a985-5adb-92cc-e31982d9a5b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e9098074-77a2-56a1-a9e2-a5061b36e553",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:40ad45c1-ba01-50e2-9770-64993e562344",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:30c41d38-f9e0-5e2a-a723-4e9759749f35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6051816e-19e7-5bfa-b6c0-262ac46aa727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c7a8017f-d6d4-57b7-8860-847cd9ff57c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0817d93b-430d-57d5-b29f-e8bbe809c78c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0343697a-15c6-5a82-831f-60b441e9acc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:82770303-296b-5141-ab09-3520c8c916e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e7be2fef-7e1b-506e-a1c6-9dbee7aaf704",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:816973db-e381-5d4d-936b-69841dee904a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ff75269f-cc24-5eb5-a66c-1173228ea324",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8526ea7a-2e24-5871-baf6-91b089d23e32",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webflux 5.1.20.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c02fbb5f-a140-5406-a171-9571c2da07f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9682e005-aa81-548d-b2cc-1a4354108577",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d5fe4ef8-ad7f-5a06-a804-f5b5f2615f6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0488c861-603f-5da0-8e8f-d56e80468f1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3201601c-277e-5f23-8fd2-a32432af874d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:877ac5f0-f391-5044-b650-9fd7f3c0b519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6d3f3f4d-14d5-5f43-bfa4-9dbd22f08907",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:61350f9d-a645-583f-8772-7e44c90516ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:52d3ca62-328d-50ed-b426-d4c3fadbe14a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d3605856-7be5-5e21-9dfa-5519a2f0935f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8c30920a-bc90-5bf6-a67f-c2ef2defcac6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:806088da-5119-5a34-92e4-c7a34be31e75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4bc3f3a7-d89e-5d08-8831-218a0c6d59ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:638832fd-8360-5039-bc0b-0007b5965f90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a4c25ce9-df38-5bd2-98b8-add4ecfd528a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework version 5.1.20.RELEASE-tuxcare.2 is NOT affected by CVE-2026-41840. The target predates the vulnerable architecture (PartGenerator/MultipartParser) introduced in Spring 5.3.0 and uses a fundamentally different multipart parsing implementation (Synchronoss NIO Multipart library).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3d986a7a-0379-52b4-ada3-87eb5dfda3c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7ba50f39-14e5-5dd0-a284-0620e6d3733b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9580e21-c7ef-5d0c-a77f-07e4b87f4bb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e19e182f-18be-5aa9-847b-208019bc54d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cbd68a98-fa07-5fbe-a2a2-76d47b37a29a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cd0c1872-e8ba-5186-b6a7-7232cf5d5224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8883c8ba-50e4-5aa1-bbd1-bca8c71442a6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux. Spring Framework 5.1.20.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and predates the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5e3e6146-34ef-53d6-af35-26f7eb2f4d28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bcf2f2e6-8e19-5176-b45e-b9f9bb3a1687",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8734ea8d-90b7-5759-a374-95c6e05cee29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fbe8eb8d-8a0c-56e4-8edb-4a25ff96ef32",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2da9df41-820d-5369-ac86-3d68c6ead20c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bee7946d-1a7e-5c42-9e7d-9655b86e5e64",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework version 5.1.20 is not affected by CVE-2026-41853. The vulnerability affects versions 5.3.0 and later, where a new native multipart parser (DefaultPartHttpMessageReader) was introduced. Version 5.1.20 uses different multipart parsing implementations that do not contain the vulnerable code.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0804fafc-3714-57a3-a471-2825e0926074",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d0a74e77-e159-5769-803e-a9250284307f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ce0ebcdc-ba71-5d81-b893-eb7429f39e74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1c9fcc4c-75d6-57ce-ad02-d159ea62ac53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:83808520-21cd-5947-9bf5-77015a0a3b95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:079e1ec6-262f-579c-a9af-350557b2a82f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f962d671-ca7b-530f-bad4-40a1a796f163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3bf28a8d-44dd-50e4-b11b-0bfaa9819dd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6659a2ff-b161-5e0e-975a-83c95a70d414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d6fa4dcd-01ba-5ede-8527-7060571ab408",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:39a21454-9079-5c51-b730-049605c611b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8500e724-b830-5e77-8934-0171d25e78ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.20.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.1.20.RELEASE-tuxcare.6"
    }
  ]
}