{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb816421-9fd2-523b-8b2b-6e9039bd9825",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2",
      "version": "5.3.20-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b97f0af0-99ec-5bda-925f-6b57d09b95d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58dfb7fc-b366-536b-85f4-339d38cd8c59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0d96b0bd-51f4-5782-8fb3-65c31221d9c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:750a7a48-1eba-57c2-bbcf-c23c64e702e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e623cb8-c906-56de-b8bf-e225f8de6821",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3618d2b6-8e78-5318-9ed1-7a569d8fe389",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a24a109f-0322-5313-a736-0dfb42c8a102",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:86ff017d-495f-52b3-96cc-47c0bc17e9eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b258874-f275-5e92-9a72-205fa147bbb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c3f5cc2a-721a-59d1-a151-cc9c1042fcc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ee2bde39-7a0d-5d7d-aa98-24fd641a4bc6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0d97dc8-f55c-5b7a-a98b-747f0c527b30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e289e12-4298-5a01-a00c-853a023194f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:93444680-3904-5351-9d8e-ba6c0e7c5bd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:613b6403-3942-50e8-a706-9e2797be088b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43d0ca06-998e-596a-a6a5-63f5da19903d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0091e63b-a47a-559f-bf9d-c0f0f9dc2d9b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ce98755d-a5be-5c56-8481-80436f733c04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a3ca83e9-b9f9-53f8-8178-48b984308e2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c56c9398-440b-59e7-9594-4581c679176f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff1414ea-4f97-5bc0-a5ec-7943f355037d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fab60c5a-b8a5-5d54-b214-df128c345833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e83b8fa8-bacb-59c3-8d18-35ae29942adc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:90e04bb8-7d39-5f99-b436-fd8716a81fdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dfa0f48f-6789-5b9a-9d5e-13353e957f3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54e62ea3-9ca0-5ed3-b340-0121ed2abf6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b24aa050-35ea-52ee-a57e-f2ebdd929455",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c6f25166-429d-54f2-bc7d-d98c73a7e7e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0ea17b81-2ca4-506d-b93d-392394689bc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1f655cf7-25d5-5cb4-be71-6247f4f2f1db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:608a3f57-5319-5104-b5db-12119f1ed9cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5379172a-ec38-5c1f-83ae-1c2784b6f40f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f036949-5c58-5210-8590-f2ca018b885e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e39521c0-dcc6-569d-baae-7ae27fc0adf5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e8fe0e2-a337-5236-83ff-c375f54a9788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b3842e82-8ae1-537a-b2d2-660de6d1322f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9ea41c2e-7766-57ca-aa03-6734bc8161c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1bffa830-6425-552f-be76-2b1fa4646412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:20f26335-c17f-5d8d-8555-03906f459c30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cc6fa931-4572-53c7-8658-f8db901897a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a678951-dc3c-5e26-ba1c-40a646621989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0b1dd418-57ed-5861-93e6-616e87dcd65d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4cc8bafd-de57-5301-a074-4be4faa22e3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60f41b23-6d8b-5a02-9178-a8d9b856201a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b93b5418-ca6c-53e3-ac1d-7bc19aa05479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c62f7e68-6234-54f2-a639-f13215af6b71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9ee5e4f0-541c-53e0-9c63-1912ac310751",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5fa57f6b-b35c-59fd-8587-3f0cad4bfd49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e91457f-19fe-50b7-9538-8e3b0da85b96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e57ad8bd-ca73-58da-b470-4bd79a206c74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e811a736-f76d-5f8e-aac0-3293fab8b92c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b03414a4-3eef-5f89-94e9-62c733f9bc4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0af79620-c0e1-5984-9553-f323da1ed091",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.20-tuxcare.2"
    }
  ]
}