{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:20430049-96dc-50d4-9e91-84efdc805a31",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2",
      "version": "5.2.7.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:42dfe1d0-2d55-5368-be1c-d24c8b8384cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:132574fe-81ba-502a-98dc-4faf653a3917",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3b879b6-0a10-5c86-a5bb-3d92e3c1917c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ea76e2a-33de-5df6-9f04-7f80152137af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:185ccd3f-b4d6-5288-a0ae-9ac6ff800bf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f539b48e-a149-5d57-b4c5-6b20ee7a9ed7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ac34cf1a-e583-5d20-b886-51839323b677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c8d293ce-1e78-56ac-a54f-cc832620a692",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:01ee1bba-6f67-58d3-8416-a519f5ea3c85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:496f1f0a-a19d-5507-aa6e-02b0b12057cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2c27ca92-5a84-56b8-9ffc-4d450becd275",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:73917eb0-3a29-5986-a2bb-740d63a7f590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e2202df4-2bd8-5d60-b71c-f5c7f528267c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5c5a6ab3-90f6-57a9-ac02-263ee6f5cf0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aaab6bca-e9a4-549f-a0cb-ca1bd3957ec5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d8e2ca9c-596c-5168-8265-a522f4e3339b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c3fb691c-9f7f-5cdf-a179-0e325c7afc90",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58bf4b6c-f1d8-5c42-9552-1c454177d488",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc04c137-c12d-554c-9401-17764083c4c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c28d7e15-c71b-552b-b4e1-39a8277cf975",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6e5a89d9-fb0a-519c-9e25-a0f68ddf0c6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0c327583-2cad-5602-9082-17f49824d417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:907f477e-068e-5308-b8ca-fa8e2402c8b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7a4dff55-f63e-5597-8aa9-41776f76e52f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:16859a76-8a34-53bb-abfa-0271ab31e0f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:510f087a-10a1-54a5-a912-9db54db4afc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d98959b0-476e-51c3-b2eb-14a863e77009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:30b417bd-89a6-5e4e-a5e6-b6bf14acb4a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a3befa6f-fcdb-5abb-a014-0c4c413ed7a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1165ac58-a26f-57c5-8f7d-8f1d66b49fc9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a5b29efb-df4f-5352-b430-bd7283b141db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1a83ee24-d4ef-58f1-9b3e-fafca9870920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ab475486-0ebc-5710-a0df-6c81b12d44da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a055ac7b-b2ca-576b-b101-34a20d2baf88",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1a3e4677-75d3-5846-9931-ea32a326089b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f3f16f6-e3b4-5240-a41e-dd1b6cf15d3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:13528e2e-5351-5cc6-9598-dcb443c80a5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:78ee38b5-4145-5fd9-9aa8-bde9eb6fcaa4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f1b28d9f-57bc-523e-8182-51e9f0217f98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c9e1032f-04b1-5ed7-b901-501be6d4d04c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:05528462-2dae-5439-91e8-e739c8d62608",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:55841cea-cac7-5f79-b5a3-c6fa6fc217ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a53af54b-72ff-55c4-bcf9-12ab34409167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ee7ff280-1b28-5089-9538-64eba8b4c309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b7e7f055-0658-5200-b647-d4037eb749d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a5be22ea-5409-5126-8134-081793ec07d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6b312e96-03b7-53ce-8a04-ad7c4095467b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f34ebe8c-2123-5c7a-8da5-49f10d9489b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f050fd42-1629-5620-bf02-4d6866d771e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17147839-82eb-5040-91f0-0872e01d5cfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fe893e39-cca7-58f4-835c-70e394402814",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7fd680c-926b-5e44-9c63-5eecff74ecd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17e4fa02-9d33-51a8-9df8-aa2e8616d191",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7cd7c95-c3da-5686-849d-923cfd06efa0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9fd112e9-b8f8-5230-8dd0-59eab9bd257c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97cf804e-aaeb-5ab0-ae46-e505da27eef2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6753e25d-8474-5d60-8ed2-5b97510b35e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54f7d4a9-c056-5331-a42e-f9649fed223b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:674f63b2-766c-5f6b-b80a-14e1c7dc3e5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.2.7.RELEASE-tuxcare.2"
    }
  ]
}