{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a31654bc-fd4e-56c4-854f-4d3abc116585",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-webflux",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1",
      "version": "5.2.8.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dbd2ebba-c2bb-56e1-b4ca-eeb72ade00c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d366f1ca-40f5-5c74-aaf6-abacc0583db7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ad0ca28-2409-5a8e-8d07-2b237d5fd8f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea45d445-03a8-58d4-bfd7-7287c018b604",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a10a2021-b9cf-51e4-97b1-6a09dce35db0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:763659b2-5b97-51a6-b8c4-398ceca4f7f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a219506-672f-5482-a20c-93bc81445252",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0abde670-c0e6-58e0-9dfc-932964738cf8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ae950d88-3d89-5154-80ae-8d6a133b4198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a83bf756-f4d0-5bb3-a79b-cf2d40f6871d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06f2813d-0abf-58c5-b15d-c745fde05eeb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e385e889-6a9e-5b01-99b4-ba6a08e30f26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c12dceb5-e44b-5b02-b631-2818c409ed2f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cda7a124-f42d-5220-a218-02d70a22a81a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cbe44420-7491-5ef7-b12f-be38451c5e80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d341bde0-4909-55cf-8316-265a6eefe39e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9d0cf3e-4fab-5b24-b641-85f98b61b483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:47e0a97a-03f0-5fbf-9c89-328bb7a5d556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7fc20bcb-b5fb-5e82-aebb-d461d8615c56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53489c29-3c44-5568-85b2-34eadc0382d9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework 5.2.8.RELEASE is not affected by CVE-2024-38820. The vulnerability requires locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, a code pattern introduced by the CVE-2022-22968 fix in later versions (5.2.13+, 5.3.x+). Version 5.2.8.RELEASE (July 2020) predates that fix and uses case-sensitive direct matching without any toLowerCase() calls. The vulner...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8faaea13-6db3-58a9-9bb1-cd10ec181ff9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fc155aa-4492-59ba-a797-bf72f3077526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0467e260-aef4-5808-92b0-e781f744e1be",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux. not_affected \u2014 Version 5.2.8.RELEASE is not affected by CVE-2025-41234. The vulnerable code pattern (PRINTABLE BitSet without double-quote encoding) was introduced in version 6.0+ on Feb 1, 2023, approximately 2.5 years after 5.2.8.RELEASE was released (July 21, 2020). In 5.2.8, when using non-ASCII charsets, only the filename* parameter is output, and double-quotes are automatically percent-encoded because t...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a414957e-5844-5b99-bbca-742f02fae3a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0e507b9-e3a2-5fd0-90cc-d0612352e4ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c66adcf1-c23c-5654-b607-3be0fa0e573e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c9705c77-0023-5872-8553-32dd151c21ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed62f525-e6c9-54a8-9621-9db2fb7cbab3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:003936f6-f54c-52ff-8ccd-cff21880235f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5b86d64-e626-514f-9142-35b6bc707aa9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6035e149-ecb5-5da3-ae9a-4654858ad37d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9bd923c-d8d9-5079-af16-9746ee2b3d39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e8f5620a-f205-50d4-82b5-b66196ddbe0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:baffa582-2971-57bf-9a5b-56ee062a2fe4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2147a0ce-9e56-58dd-a2af-824b40cf9036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8fad00d2-3960-58a6-9e92-c4a491f055da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9f893a20-d740-5dd0-b7ac-4e7ff0eb3e83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:98ba9583-4282-57ae-8780-961161c3c17e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e440b47-a079-5663-b7b2-5055727bb481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:90a4fa7d-3290-5109-9a6c-3dfe7c8c9176",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1972b5c-94b3-576d-97af-501fea5ecf0c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ceb6e2ae-e00d-555f-b526-3650c01fa21b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:135cbf07-d561-5526-b0f2-d6bea7e4eb47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76b7ed4a-230f-5aa7-96aa-5996f69019bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf8ca4ab-812a-5f9a-92b2-90c1b44c872b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d29ccc0-cc2f-5774-a6ea-4a6762d0c2bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b3fbe410-fda0-5270-928e-bddab5855f11",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd2b0fec-0b04-59d1-bfd2-9cd941ae4d1e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:86e099eb-0126-54b1-8da4-1510efa7817e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:96a4a226-07be-5d54-baba-e50ecdb97644",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5ad8fa52-aa0f-5def-81ca-927eec80cb86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:abac7e71-7d01-5a41-a45d-22e04a2e0285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6f07866-6991-5c84-abfd-8a1785388c19",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f5ca73f-149b-535a-9bda-ead792252d14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4903e06-0729-5dcf-a298-8cc69800b67b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1224f987-d872-50bd-a031-187489b5f3f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5a8f9c62-fccb-555e-8c44-6377409813c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a168ece0-adfb-5ee3-849f-1c94dd3ce2b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0665dac3-387c-5d01-9f7b-8a3ee70668e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f4c5e433-afef-5e92-af67-a89f50847469",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a48b2d43-720b-5e35-accb-b62931b9ffe1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-webflux."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.2.8.RELEASE-tuxcare.1"
    }
  ]
}