{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fbec71c1-9dca-52de-8773-e37fb8f2a884",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.30-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1df977e4-9896-5740-8e16-6484612f5db3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2be8db97-2bd2-5c22-b281-c39af837c2d9",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:750e96ae-1a0c-50b6-8127-e7910cad8495",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e829b575-26a2-51c6-a1e2-6a4794f2ace9",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c9ab6d-f6e0-5006-967b-3ab67ab00764",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465d2cc7-b636-56ac-99cd-c4d619942b78",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42608c2a-136e-5655-8ece-370ff47e42cf",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:844a23a9-ae4a-5d84-a452-c9eb1f1ea094",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ea509d-b7a0-5367-9da0-8d091ba48ff5",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3ad305-33c0-54b7-835e-8c1df0b04475",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49635618-7bae-56bc-8e1a-885f53890654",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be58d0a2-fe16-5082-a0e4-88e94e8d9548",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ac4926-f85d-52d6-9a22-e9dc5441de62",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbf2d9b3-d8b0-5e91-a15e-42173c2a0a3e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:237a26b1-d616-599d-95ae-59838375ffe3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58a40c11-644d-5221-b4c2-a877bba55757",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c7b544e-f11b-5e34-bf07-02673c522d7d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34af550-d9fe-5054-b0b5-7b8508258bb2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf77de1c-c54b-5cc1-9466-ab6545acee7d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cadebf8-041d-5408-babe-c733684991a5",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2d25186-f2a2-51c8-9b10-4cb5c409e5e7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611ea7b4-fde4-59e1-8aa5-140a13c42f1f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.4 of org.springframework:spring-webflux. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cfad593-f8cb-5dd7-adaf-9e0cef55a4ff",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce494c21-1fa2-534b-9162-6944a03ad2c0",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ddcbcda-78dd-5899-8fba-759461be8b18",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c253c51-c074-5a72-86d3-2ab3eb65f276",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbb9a83d-916a-596e-bb50-ac5385f2edc7",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c1dd4d-7713-5971-b8c2-ca90b8b183ab",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6679a439-02a6-5612-99e0-a4f5700ab823",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b5025d-d573-5cd7-9b8b-f6c93e1a5d21",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:976b0138-14be-551a-ba87-06502d22045d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b523ae45-0ab2-5214-a5b1-b6bae8e098b9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24ed9da7-c997-5d64-a9b5-31af055b832f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bc9f38d-d97b-5492-99bf-7a48b1421c8f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465555c0-6dd4-59b2-bc5d-da1b6384f781",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5153bc38-8c97-5951-8230-9c5f8c69ed5b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.4 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.4"
    }
  ]
}