{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:06095772-1e90-59c7-8b49-bdd54a31faf1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.39-tuxcare.13",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fa56f8c5-c117-5f89-abfb-18b1bd79cc7a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc764406-ae91-5230-997e-6765afbd9dc8",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-webflux. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ab935b8-9f3a-5875-9bf3-9f2133dd2fb2",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957617f3-b35c-55c5-aa53-93f9967844a4",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2153b281-2bdf-5b9a-99d1-ca47d4be4a19",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bb98276-d701-5fb8-b218-8eeddccfed44",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1aa71c2-a871-5f08-a6b6-ccde40f45899",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebccc283-f90f-5415-947f-8baeee71680e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.39-tuxcare.13."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d788ba25-df24-5d0e-98ae-5143a1bb7ab9",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ef0a5d-3999-597d-8e8d-bc0fe55cb0f4",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f1772c-d3fe-5451-8b4e-57bd9ac28209",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:644555b5-929e-5a67-9395-1a24b9ea32cc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f13d643e-3b93-5573-a333-3dcca2e859e9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31512dda-dc28-527e-91ea-867a79f95173",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cee1b65-91b7-59be-aec7-ec9305c199be",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9d9afc1-a10c-510d-a958-c0d1b8ab2a94",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49f959c-2bdd-510e-aa08-edd07e282569",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bdf0b06-b76d-5f9b-b64f-71627e7b0c15",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9b7d13-6ff0-5ac3-9fe5-2a69cb841c84",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.13 of org.springframework:spring-webflux. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61121e24-2db8-5973-bd8f-24fa3d1bf5f1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f51b55-5779-5770-8663-68d3bdea747e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c65f8d50-9be6-57a1-a001-2155b1cafeca",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ce7d776-c918-5d9a-bff6-1cec5b67b6d4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3d5ce81-405b-5a09-b19b-776f8a6ed922",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f183cc44-5249-503b-a401-acf50f36b328",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3b1f930-6db7-56fe-b718-23083e4d3286",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3076a910-b039-5f6b-bd98-99191acc2ca0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38db062a-d3fc-5826-bf51-1a344a2614f0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd4461ef-9125-565f-8405-00d6181df6da",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7c3bade-2430-5d75-8d0d-8ae5e1d2255f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edef49f9-c52c-5c21-a251-73d932c63e6b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea8ca76c-8ec1-58d4-b476-1707f554ce62",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1aface9-f152-5e50-93c3-bbaf1f3f4313",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.13 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.39-tuxcare.13"
    }
  ]
}