{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:07708ec3-85a3-5962-8170-a81de91b9e65",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5",
      "version": "5.1.5.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c07db777-64db-53d7-83e1-00449f4984f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:71a6f5fb-d6f3-581b-b3f4-dc01d108bf6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0dc2b0ec-8457-5b08-834a-936f0c0acf63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:45da9461-2294-569d-9c5e-564a68b3936a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e1e00cd-760f-5acc-a2dd-e31b3c919c4f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b0d242a9-63bd-56cb-969d-9265669e9e21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e859bfaf-345b-5e6a-b6be-b4e1556791bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:43324472-0aa3-54de-9663-96f110d5d165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c8857011-c8f8-5bb9-8d79-03513fade3a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6b07313f-e7c4-5e97-b0e1-7853320a212f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:df26de0f-9049-5e06-aa2b-58c243bca95b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c366ddd6-0d9b-5c12-8ce5-27616c714b26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2f78feb4-d125-5d33-9bb7-8f026da30a2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e98e1481-4031-539f-87b0-949dcd80a31e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d39ca25b-9828-5184-a26a-78cc447996a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3491e637-2370-5519-9c08-c0d04f4bfe4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a763f79f-03d4-5cf4-a827-e85b7588061e",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webflux 5.1.5.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ebbea81a-ce08-51be-a7bf-70e1adf808bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:02e85135-29e5-5c28-8c87-f02d352f326f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:994e8ad6-af49-5056-b814-dadac928f175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7ccbada3-6853-5528-a0d8-9ee78f97fd9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:61aab037-0a53-5954-bad3-61b2b29d20a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:397db30d-65e8-5fcd-a81c-b9f365af1434",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1fa7d22c-fb07-53bc-85ec-a5fc21f889a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4df0d982-b1c5-5fd4-ab95-a3ec58343b4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6f8411e6-18ee-58ce-b264-3d172aec0c13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1c01be86-ebde-5b42-8339-bc730671bd81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dd14ed53-43b9-5e7c-93ce-1c9b908affda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:133a28fa-2ae3-5361-b86c-6761ea673bb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c208370a-c316-5def-afbe-1949eb8547f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c7710cdc-bd3a-58b2-9b71-7b9c0ef14255",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b1fcd04f-48e8-5701-8864-4e048337c799",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0e38e2f0-3dea-5b59-9b16-c60f2f4c0078",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5f181718-1e09-56cd-9bf8-e6525aed3f06",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4758d248-67f5-5bce-873f-56f9d87eb441",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c9ecf379-737b-54ea-a684-2123ab57b6fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9e27e821-d81d-5afb-853f-4e13d16f654e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:745980b8-4b02-58e0-b37d-0c0b1d32f3a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:591534af-cf1c-5935-a1bb-b92e7cd49ce5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1aedd59e-6001-5ae4-b79f-dff69cb61386",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c614987f-588b-5363-a15b-e1b5cdbbbb7f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f6175189-1267-55db-986c-8e2656945ee7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b833e1ed-167a-5ed7-9c50-46010643ce11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7683dc91-3263-5b1a-8a7c-0bf57a865a30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c5704465-2a36-5532-be1d-b6b8577354ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3b8a73d7-62e4-54e0-bd98-5ebcd1cf9572",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:443e418d-9143-54e8-98c2-94651cd6c3aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5980fd1e-1ee4-57c0-b24a-1ef3fab6f1ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:939322b5-9158-5867-a0c3-637382cbc71c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2880f0d1-2629-5a3f-8d98-a6138860791d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:722f77ec-2e05-5769-b4e5-a43150971470",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:89d05410-d29b-5ea0-81d5-e8293509e7b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:27a46045-e564-5d9c-8bc2-800dfbe0277d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f8f57f64-7913-5aac-84b9-887bee2180f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7869f607-bd24-5adc-8776-078b9d28f527",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d9ddc304-63fa-59d2-8857-2f980af4aae0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:88bfa9bf-40c9-5ec1-8710-c071cd87bde9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a19bc27a-0c20-5ce2-96d2-f4b2d384e07d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f265bb3c-4951-5336-b9a3-370478745731",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.5"
    }
  ]
}