{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4abab9a9-ed5b-56db-b941-fc7ba3c89437",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.25-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2855d02d-0c97-517b-814c-03ebe89ec962",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e36ce4a1-f56d-5ff0-8285-62031af04d67",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5e34955-278a-59b0-b3bd-8a0d8c883a8c",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690bf0c5-4d9b-5cc8-b9e4-b88b35d75d7f",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a76a23e-9e89-5c70-aac6-7e4f31a745ef",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:280c2155-e59d-5c5f-89bd-cdd0509b18be",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87537308-77d1-5b8a-93a9-9685f397dc69",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6887c21a-3c5d-566a-a1a5-7311a8226603",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79057fb-c61d-5666-bc37-1453cf9fa70a",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83cfa59d-2756-5da9-a669-5aee82d5750d",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:706ab837-717c-5a48-a8cf-bb505d55a031",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2047aae-5afd-5ac6-a3e2-bafd37bcf33c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c872e8f5-ee3f-59e0-bca2-f2e83c4f0e6a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ae83076-6001-54e8-a9ee-8bfdbb5ce38a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8af724bf-2bd2-5c74-9c99-b85f8f48f909",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4f1292e-2033-5dd1-aeaa-68d5f57cfdb5",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31423ee2-bcfe-5364-890c-c4fe071db3be",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee65091d-d891-56f6-aedd-1cbd15d2f80d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c12d6a10-dacc-57c8-b6bb-500590841ed4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67dcb871-93c1-55ba-ab0e-b28c3e5ac522",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25857df5-348c-5046-b816-d7e0acb373e2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d525bbf-d79f-57bd-aca1-2ab593e53b1e",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.25-tuxcare.1 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.25-tuxcare.1"
    }
  ]
}