{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:532bd6db-c795-5a60-8a24-801c6db22be4",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1",
      "version": "5.2.10.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e348361f-bbbf-5e06-ba59-e9075685870e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:389c5bd4-5847-55c4-bd17-ec0703e84e95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:980d0018-4ce6-5933-b747-32b0019d2eac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3412ec95-3ac8-5c5f-a808-0b4ac891fdf4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3528b486-1831-5f7a-8d52-edf3e7500dd1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:972c3f78-0051-57e3-b932-6b840f3f25cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81c2c1cc-59e0-53e6-af1b-439a54512d02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d57780e-ac02-5b5f-be84-8af7e8ba5c40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c44798c0-a113-5419-b5e0-72959d3f4937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d4e1682-ac88-5b81-b0c4-e8601a13852a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5068c92d-3473-5ad5-95fa-de5e083c6da6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20d88af6-e7a7-527d-9fe4-be752e8abcc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4f223129-ddce-515e-b3f2-7686a14d7e64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3b04cb9f-d191-5124-84b8-ed9f32074f33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49c42afa-cfb0-5c0e-99cc-20bfb18412a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:18dea628-921a-5576-a9ff-edc2aff1e070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb693c70-9fd6-5ede-befa-c1bb888eed14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d0dda79-fe7d-54a8-a3d2-7b4ad9256539",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8080c20-1d68-51ee-85a0-c8083f4bd5f4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux. not_affected \u2014 Version 5.2.10.RELEASE does not contain the vulnerable code pattern described in CVE-2024-38820. This CVE specifically affects the fix for CVE-2022-22968, which introduced case-insensitive field matching using String.toLowerCase() without a Locale parameter. The target version uses case-sensitive matching and does not call toLowerCase() in its DataBinder field validation logic. Therefore, the l...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54e57cb1-84ef-52ed-87ee-1f9cdc02c13d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1fd740c6-e089-5fe0-9e17-b0df9d7d2f8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a2a72a3c-447a-5b08-bfac-ec424bb0aafe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0cf9f697-73ec-5393-810b-7e1b1135de4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d052fa2e-4f1f-5cf3-bca9-f9c6112f207e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d069a9ab-5d58-528c-b929-0650853a5da1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ad11b183-c7c5-5f5f-825d-f6cb22e1c269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ca7bd5f2-5686-505c-bf2f-a215e5003f02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5f6bc19-843b-5581-8a6b-82ef7d7f5c16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4e1d0ca4-ab7c-54d3-8172-c0a9ec5df405",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:89590e4a-8228-5a0a-b223-a5c6e34106cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ab6ddcd-e560-5053-b8e3-7d06f54cd270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux. not_affected \u2014 Version 5.2.10.RELEASE is not affected by CVE-2026-41840. The vulnerability targets the PartGenerator/MultipartParser multipart parsing implementation introduced in Spring Framework 5.3.0. Version 5.2.10 (released October 2020, before 5.3.0) uses a completely different Synchronoss-based multipart parsing architecture that does not have the vulnerable BodyToken buffering mechanism. The vulnerabl...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57fc7dcf-7525-5d68-9a5e-94113871c205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e9515a41-0a3d-5231-acc9-2f5c575c3e58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e26c30c2-1ec5-5a76-93a4-f823ee9a8bd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:add69823-b9d9-5b20-88b4-5a4273f5133d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e6deb10-0da0-541f-8b59-221b1495e7b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ce6a932-e86a-5d84-9887-6b07e90113a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb0e384e-9a10-5ea7-ba06-5d69c47313ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b772bce-6131-54ea-bf61-c5ad7061d5ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d1ccea4b-fecf-5ad3-9bf9-281925d4b6c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d7cedd5-d668-5aed-b19b-14a93f251e43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8bad98e2-935d-5ddb-86da-cb737cc96e87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e64bfa2-9c62-5b6b-8af7-6b559bf3c25b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2789770f-79a6-5a90-a20f-432d2f131b71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4c5e3f8-61c0-56a8-9fbc-50902aa55cde",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1250f0b3-5adc-54e2-8be2-a481ab92ad04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:09527f0a-f5b9-59b4-b22b-24d63a60b7df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ae34cd9-9083-54d0-a02b-d819b60c170b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7cf143d6-411b-5a77-bd35-f231f732be83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:284f2e48-b9aa-5def-bd3b-2e77e71fd44d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4927f0a9-147f-50cd-8892-e1b71ae3a45d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ffc410f-2e95-55c8-92be-3598489d8567",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:792b1659-2b3d-5499-84b5-1bddf25329e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f7f37d7a-6c0a-52e3-b03e-254224eaa9a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7fc6b6aa-107e-5e50-96fb-9db92a13b5c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ac17731-fcfb-576f-ab83-5861f3528688",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e258d764-892b-52af-8725-b7bd03a96b5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2a215a81-ed46-58ed-a8b7-e793f2f4e726",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.2.10.RELEASE-tuxcare.1"
    }
  ]
}