{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:16d5371a-61ba-595e-96f5-ce2affe17fb5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6",
      "version": "5.2.0.RELEASE-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f9aa04d-b7c1-5f09-965c-6a90eaad1ae1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:00db2c3e-b5ae-5a7f-ba68-7f84d7f47da1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d74db062-62a3-5010-bc04-f69d53291e3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:680a7736-d02d-5d6a-8f79-bcce6319fb57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6a2c1563-f9dc-5332-8ac4-64d570ce7c8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1a129ced-7c3c-5651-ad1b-212adab922e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:69cd4249-f456-5991-bd10-cca7351d25ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a96253c4-f166-5587-9660-d204bd066995",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9de36b0d-8bea-5c0b-a397-8f805bf1f762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:64b7d895-2bde-518c-9e32-34478a30fc32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:05ac1788-8952-54ea-824b-7361e9e969cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:24213261-3f0d-5ac7-aaf3-4f428bdb8aa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5304b681-f1e0-56b9-91a0-dd6af0de4971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7e4677ae-8525-5af3-9e08-50eb4d5484a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d3574bbf-1065-52fd-ae35-d5fc8ecfd5e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d204cc0b-9009-5e96-9694-0540b1029269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aaaa9876-847d-5ce3-9855-700cc73ee614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e912a750-5f65-5337-b855-4781eb3c915c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9eecf4d2-c96d-5549-a48e-5667a18b6c40",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webflux 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0e3963ff-ee9c-530a-ba02-eb87f231a792",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:11d30cd7-ca04-5c0b-aa42-d2974b00a4ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9673f993-9932-5a91-b126-5e49d7eb4352",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:67f6888e-bce6-5f7e-9022-cf0948c99a4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fdbc9120-bb1e-543c-8328-214b09ef3cf1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:923825c7-5e38-5c3d-b6a3-6f186be08631",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-webflux 5.2.0.RELEASE-tuxcare.6."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1638dbc9-8e34-5bd5-b9d6-3fca39160f76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c826d4b2-97e5-5e16-b432-5d52195c4665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4e8ac9a2-bd59-5c00-839d-97920ed71439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cf92e6cc-afb3-5e35-8025-8b0253ddc4fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:48206f1b-0ba3-5320-b8fb-d5a4568592d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cb58ad12-d3fd-5b0b-ae7e-0f41cc2f3a85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b18d9f88-65e9-53fa-bb9a-17cbef215de3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:19ab2ed0-f6b1-5f2a-8eb1-21c35e509ac4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3cd0d0ac-82d7-58d4-9299-6356b6f42955",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0e5d7f8b-cb66-5006-9481-2504a4c231b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe270022-45d8-5e19-8f59-43e2e4fc6aec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:29cf26fb-164c-50da-8534-22b126e18d56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:457aac60-102a-5d7e-b5cd-9d3e3f90ec3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a9c3adf6-1df6-5389-a292-b4906c2cc3a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ea768e9c-ed2a-51a9-81cf-d966d48f2f15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3457735a-f49c-574f-b0d7-ac45d0f2bc41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0f9766bb-414f-5c37-ae21-d1122eff15f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e364b880-9613-572d-89d2-4a52374270e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7f209ea4-7d1d-58d5-9c1b-61e37e6891b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0ea49fc3-c5d7-5d2b-a39a-5789e543c250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:702dc529-c142-54b8-85bc-6bc9adfc9474",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d52e10b8-0020-5291-9e75-20cff4d05aeb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:49cbb131-8cdf-5372-ae00-13e25308a19c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ff0ae8e4-63c7-501b-bd83-b84f5f6a63d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5d39b26b-d3b3-5ae6-9f30-5b1eafaec51f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b09a11da-270f-5b42-b319-c8b83bf9a850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0623958f-4d30-531b-b0bd-1ffa005ef928",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:549f61ca-2b88-5480-a4e2-d015996f24dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:edfa0071-a0a3-5535-b0aa-59004fc18641",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:63728e6a-3feb-5a33-8213-d2660f0db698",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2e53682e-c43a-5302-b9b9-db2f9daab12c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df4a9b53-d15e-510c-9aa5-5d0b49782e80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:164a8192-c7ad-59eb-8af6-90abb9bb1f2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fb7fa364-c7ee-5f88-8f47-31e60b88b4a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:de668402-12a3-5fb4-8f18-f239130c59bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.0.RELEASE-tuxcare.6 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.2.0.RELEASE-tuxcare.6"
    }
  ]
}