{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:82da3fb5-2425-5d52-b2ac-ab7349605d61",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "6.1.20-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:caef0dfa-194a-5846-afb8-215ffc2f1e36",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.8 of org.springframework:spring-webflux. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd784036-d980-5a06-8b43-ac060453bb3c",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:394e7d5c-7350-5e94-9bba-b6cb6158dc67",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8322c35-0fc9-5033-9647-49ecd2cee932",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1c53810-c973-5da8-a480-80a9732b42be",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241db375-dd86-5e32-a9ef-dff9ba36bbcc",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e0b21ad-3917-56de-8b20-fa2006e65c5f",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bd50231-ba0e-5bcc-a98e-d0afbf3faf6e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac0f8dd0-b878-56ae-acdd-2c7bddbb0283",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7e692f3-8a66-5d5a-8b35-4b13dff7b1e4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae60e1b1-5fe1-5b40-8587-e1f1822b0567",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb3f39b0-7d57-5e66-9203-6f030d5e7280",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:927d8819-4124-53b3-ab18-e2a1bff7fe15",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c99996-ba1d-5a2a-953e-114692adada5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c31f2f-080a-54c6-a779-a21fe05cd1b0",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3dcf0f5-f773-55e7-bbf0-8c8988c35893",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193e2fc8-b89a-527e-bfc4-4e6e59325e1a",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f30991e3-d310-55ba-a5ab-a5ecbb696c1d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:536b5d3b-679f-568c-9b4a-01c1251d54c4",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24487132-bedd-54bd-bd69-8c22c6acdfda",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c1c375-44b4-5fe3-ad91-7fb132001ede",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f0e7ad-4082-5094-b27b-30b7b0c1ad08",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ffedc99-d129-55d1-8590-6b5028e976d9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29335177-f210-5814-821d-b36fcdfdd5c9",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b38e317-4615-552a-b2fc-940a75525d8b",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fefe34f-8bef-59cb-bd7e-e0d72479e65f",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.8"
    }
  ]
}