{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:da42aff8-ccc0-5ad0-b538-74848c935084",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.30-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:43afaec6-c482-5931-8406-7f09102db76f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13182cb4-9f18-5d6d-9fd2-8f5e593548d1",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2072afb-cf85-587f-816e-da0393648a37",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a92d5ab5-d229-5154-a0bd-83c8f2696191",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d05f08-0d9f-581b-a661-1367162e2f4a",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46c8878b-437a-5573-80da-428db0be2c9f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2d04689-c624-5a7b-a6d1-93abc889c3fb",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a5d522-5048-5fd4-8abc-4a792be5564b",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c700501e-23c0-54f9-8238-cebbe8d3d1c6",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5476f28e-74c3-54c9-bc34-eb08fd07dbcf",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c648e8-321a-5430-a534-9a5c42a92151",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f8ea537-d5b8-573c-8fea-8516d9a15fc6",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1252574-57a1-52cd-af2f-868160d844fd",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b75f723-79c5-5701-8adc-5aed7277bcbf",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe42da6-bc06-5c2b-ae14-f0623c515be2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f32acd-b31b-5d6c-924c-8ba42375c6a8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eb20c76-64be-553c-8646-6a56a813730b",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe5b5b02-2dc3-5d6b-b515-92573dd72c5e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70c64a88-8be5-51ab-a0ac-d91baef4cc42",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96b60b00-4557-5487-a437-4a4bf37580a8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb71243-d7bc-5fea-960e-5b6c6d81fcda",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:405acb14-27d2-531e-9ab2-7f64274ae58c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.5 of org.springframework:spring-webflux. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df831745-b650-5eb1-8411-ebc4a9f84f34",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59272a74-94a2-54af-879d-c46cbf58b34a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36c15534-6f05-5974-a348-d97a02c6a004",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a37f8cc-95fb-5d44-b306-df26e49d83f5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa0746f-3591-5205-bc1e-d733235f416e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20ba3fc0-f8e2-50d0-a967-ac94cbb1fdf7",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cddf9bd-633c-5b33-8cb3-23a805b51599",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d79bf81-65f0-5d62-8c87-37eb77567d1d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc6c5c34-1fe2-55cc-bd28-cf982444f1de",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6f0c707-8501-5065-b3ee-44f29b0ca730",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c87272-d9fc-5e7a-bf9f-e10c3fd7cda7",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f043e4d7-f3d1-5999-b783-d78bd7fc11e1",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aed1181-9168-58a8-a820-c382bba8b069",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc93f763-b8fb-5d04-a218-7985eee57eac",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63063349-efd0-5ebd-8756-74d19711c27b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.5 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.5"
    }
  ]
}