{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:20d52105-745b-5241-a3a6-7a23ca740929",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.37-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:40c78efe-3ae7-5c83-a10c-7553fec238fd",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79b32a2c-9101-5f3c-971a-2a11efddf9c2",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39ed337c-c826-5ede-b564-d26db82e15f9",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b70dfc-a186-5cfe-87e4-2353fb9526c1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9507d28a-df52-5820-96a5-0fb3789b5959",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e109d577-6c55-503f-a056-8f8272915be9",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0043690-1419-54c6-82a0-f3604342c65f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9868dba5-b633-5c61-8d0b-00d38374e6d2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:762f773a-6f10-56e6-bfe0-4722e120e2fe",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f742486a-e711-5dec-adda-f48ef431186b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ffc0db-f447-5751-85b2-c9bbbefbe3e9",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:260c125d-4299-506f-b59f-155e416cb7f3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c343ffa4-71b5-5e4e-8578-19d827a91b38",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f736d5b-32c3-5395-bb8e-26dc9e62c97c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c2b9f1-f24e-5549-8277-8a613e6457d0",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa18f086-d8d6-5ebc-911d-6ccb49671a17",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fedbc550-8db2-545e-bb00-9feb61334ff2",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb8ecf47-d5e0-58e4-b985-a3811bfd9de9",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6735b8bd-5e24-52bc-9ccf-16686465a99e",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea674f1c-49e4-54f3-872b-d160ddeca831",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82648fc-b7bb-58eb-9a67-bb2066693bc5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c95c5243-3b09-5068-831e-843064c30c88",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea5df67-63cb-53a4-898b-0d6a7bbd3c0b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7107ef0d-0887-5466-81da-711918fe7344",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4070d576-9679-5ef2-9f75-78ad70a474f2",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2d25471-91c2-509d-9ccd-e9e521a0e95e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f3d51b-2103-5c66-b2a2-347d5a29beab",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c4cbfe8-493a-5783-8b15-b710ebcb9a08",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-webflux. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42a37b58-21cc-5267-9118-7456ece583ba",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366ddb18-5a6b-51cb-8da2-e3c0e9ce5f7a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7623dcb2-a020-5cdd-8a12-eb46439b3b98",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58751186-2b1b-5e6a-a7d7-2d3e99911032",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21fae4fc-f888-57a3-aedc-e674890f1b36",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.3 of org.springframework:spring-webflux. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a1bf60-645d-5595-a370-d6217b3db9ee",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3b6974d-eb79-5753-99d8-70eaf97742ae",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d716a7b7-9425-5704-99d9-d0134ab39efa",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff364d5-1690-58d7-88d0-d1540de46d66",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe703ee-c166-5bf4-8b13-f773290a7385",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97ce333-3a6e-5b55-8912-fddc75cb2b9a",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee04d6f-a369-54be-aeb7-a6c3027a4236",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f60f054-fdc7-573f-bd3a-a3e66beb8d66",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:317f00c1-15ab-5188-bc5d-fd511ec47b14",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecb57979-1481-56ac-a089-0114d4ddb3ef",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c7014fb-3c05-5fee-9175-9d60bdf2a246",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e2d13e-8728-5cd0-b55f-2f85b1407933",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaae8dc2-e218-579a-b8e5-a524e35f0542",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d860983b-838a-58fb-9593-446203eb4a04",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.37-tuxcare.3 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.37-tuxcare.3"
    }
  ]
}