{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f31da282-80c8-5ed8-826d-d206e3e82138",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.31-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:32b8e994-e6fa-5f27-93ed-acf74f450a95",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20c1b86a-91f0-5f47-8f7c-dff9243d7290",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fe7cb26-a278-5721-9039-692497b084e3",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e23be7ac-bf9b-58b9-a02e-e50725b117e4",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3b625a2-0b00-5e97-a261-614d4158b86f",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ad22ef9-e548-5490-be54-fe8f45a27b8a",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c15aaa-68fd-578c-842f-b35bc21a1264",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17734ba8-21d9-5510-ae8b-ed2dba5fb517",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d80c8d1-162f-556b-a7ee-26bdf359d17f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ce670d-3435-5c01-8eae-804eb9723c3c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bdc6d8c-351f-5a0c-b0d2-ded1c5e4b5df",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aff6bf05-4602-595b-b75a-564177faa35f",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.31-tuxcare.10."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa174f0d-c889-5b4d-9a9f-1db52569ce57",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d2cb38f-bbd4-557f-b9bb-043780c2df3a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af0bf4c5-d10b-5758-9872-8231f5c853bf",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:311c75c9-309a-5d06-a70e-9022308492b9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0bdbccf-6dc6-55c5-b7ca-a164ddbdc5b0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5bdf69c-0445-5f06-b2f5-6d1208316aea",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:206d2aff-c63b-533f-b32f-7c7b999557ba",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae21a32-d8fd-5b34-9ca9-bed62719b4ab",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5be9795e-388f-55ca-ac18-b73084695110",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd443c3a-fd78-5b05-9408-c45e8577cd0d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82812e0-e557-50cf-8be3-16ae64b5a9a3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.10 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08238fbe-82b7-5067-88ce-a6ba085b34e1",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea9e307b-6e9c-56fe-a840-3fe311de1eb1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7d4099-454f-50f4-b2e2-1e3099938a43",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51e1ebdb-9974-5a07-9c7e-be625646ce2d",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1acad82-9afc-5216-b65d-35c8d96167ee",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25300236-2906-5630-adae-f086d8b484e2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37048258-b2e0-5ee8-9a19-42189c864eae",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc011a6b-0077-56f4-9867-8d13556b4991",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d001426f-5c94-586d-bd51-48766f3a1895",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36239e58-130b-5e96-9b49-cc540e55a1e4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b69204ad-86a0-5328-bdd2-475c5a5670c2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59be9318-bb48-5e14-a2e4-9a4165b0d6bf",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913653d5-73fc-51e5-b37e-a23136bd771c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75b51f3-9646-58d1-98b7-cc902e3bf118",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:204c1280-5dc2-5d2f-b7cd-03726b6110be",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.10 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.10"
    }
  ]
}