{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f8744f83-a62a-5bd5-b347-92b176fc6899",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4",
      "version": "5.1.5.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:151ebf18-1ae9-5aab-900b-5ce650e03252",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e04d4808-0cef-522c-b44c-73533567fbe8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1663d713-2520-5599-b19b-7a0539b9302c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:441a136c-7b77-5b2e-841b-08d481b38fca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c564cd6f-ee1c-5980-847f-ea589ff1cf9f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:beb18a34-7d4a-597d-b4f9-68232eb88551",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:07688e95-8eb9-5c51-a15f-69a3556f23ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6324c5e3-3969-5ceb-bb5c-9ef493ec7654",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:23244b1e-ce16-5057-84ac-e44be039ac36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dad58697-7562-54e8-96ce-ab0d8c509982",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7103636c-a510-580a-8321-74b5f5bf4089",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c088a883-239b-5275-984d-16dbd269c69f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b09ec759-4fef-523f-954c-f2cf67990cdb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:57ee4fce-f1be-54b2-91f1-9d0f8a305c77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:11adb41d-34db-5d41-aa80-1625057eca85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c2d618d-a087-5cde-aa62-da86e940e920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:891edae6-76c5-5d3d-9b42-41e9d719f522",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-webflux 5.1.5.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:56cddb80-caf3-516e-bc25-1bb6a94f909d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6122f2cd-906b-5621-a6ae-ef2f60ce34c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7b04853e-aee1-55bf-b130-95d2ebd4b824",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:25a94e45-31b8-53d7-8fe7-91cb63e07dbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9fd98a73-acbb-5e90-a4f3-e3212c64a3a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:05b55ff7-edc0-5543-b40f-c119533f003f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0ca1d8f4-c59f-5763-8a45-beffef3eacf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c1b94847-88cf-5903-ad6f-6c7232e6eafd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c07b9aa1-9417-5cb8-9bb3-b8f9ccf6062e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6e576d54-83f1-574c-a975-c383a7ccabb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7ab1d3a2-c573-524e-9531-49ec88f570a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6dd7c779-94fd-52e7-97d3-78674f65d529",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bd1670fb-7d9f-54f4-a6a6-828d8fbbc53c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b648e128-2a1d-50a5-af7d-6d05f4a42bf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2ac029e9-0b56-54c4-9961-2c2ba9676f30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:119a6c2c-0523-545f-bf71-37e0bf97c966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dc98e85c-1a1e-5a3a-b6b2-2a6e42f54e4a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:572f052e-1b67-595f-87a7-ec92bae83b3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6a194b51-7717-533d-ae00-86acb5394b66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7e399787-2b45-5c8a-b2a4-a3ccf1d4e5fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f4e1a092-fa17-58e7-9398-4db1f5583a04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b84fd366-3622-5872-8ad1-2ccdc02cede1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8889afb3-6a62-5017-8ef0-0e85c73723c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:52ef2d60-2df7-59a2-91de-45d1bcf16bc2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a7f35e7b-46ba-5c7b-abf4-9134341f821d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1d5cf50d-31f2-5de3-84d1-7d52be270079",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:42b6b1c2-c4f0-5d86-bc45-5e8cfac99141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f827f0a7-8365-5365-ab08-4e37fbf802f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:23f6277d-36ac-5fcc-989c-75a6edfe5e80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:18473c83-bea6-5868-913e-7ee5e1fc543f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5046cb8e-92b3-5292-820e-69d458b3f4bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:feb01c3a-f304-528c-a546-55f7e4c485b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:050a39f4-6af8-5af2-91fd-285413a1fefe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b2c6b661-4fdc-50de-8c0f-33896e112980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e49a45c2-e12f-5bb5-921f-2ec7c5d6b635",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:96e76f27-dec6-5694-9c77-101f981bfb8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a11dec60-9c03-5dc8-8126-eb1d9b3b5650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:07444ac8-3f30-552d-a6d9-4060b62a4914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fa9b8f65-3de6-5032-9ee9-c75ea58ed4f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7d5965a2-0f60-5892-96c6-c8e5da498b63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:209a3fe8-26ad-5435-842d-ef5e2d8b9ec6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1c29a82b-4b22-5ebb-acf2-ada466fec0dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.1.5.RELEASE-tuxcare.4"
    }
  ]
}