{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:890d6bdc-4f03-510c-b348-dbdfc623ad64",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "6.1.20-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:80f3b35f-622a-5123-b63b-c41bd84a5fb5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.2 of org.springframework:spring-webflux. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70d68d6a-fd30-5fa3-821a-65530dc05430",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a5edb99-9168-5967-93c4-f99c0ae40715",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d268f4a8-2a13-50b9-a62d-ce0febfd435e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:669d0c49-4651-5b89-8f40-f56be9f16648",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:089c27df-af25-577c-8fa1-d95b049bd4d3",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5684875-0825-5259-b7dd-c1564ca5e985",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51c6f53b-caca-5af8-b5e8-b69569764dc6",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29748199-d016-5758-b690-64879f4e8fc6",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95e0c8fb-63f9-5103-8256-ae16b744ef07",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f235f734-e811-5018-a4ce-40bb37657dbb",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7535af28-b544-5852-9844-55200602b499",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51603c4a-7ccc-527b-a791-fec2a3d6085d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b23f911a-963c-568d-a5ed-e03b9f6e3985",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a587f308-98d9-560a-867a-f32ae8eea57e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d83ab03e-642e-5f7c-a121-6583c28c7c8b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37f48c36-a711-5c0b-973e-0966b7533e35",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696f4bfe-03fa-5ae4-bc26-277bd36c267e",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d94c4bc3-6a34-57f6-90a9-702a9eb424a8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbc6907c-5a68-5887-b208-8d2ae9b595f8",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3727aab0-3739-5c75-b861-d293d8dbeaa9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38060634-ebca-568b-aaed-cc717e5acdc9",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:305107d1-2b87-53d1-a062-62e1ad3880fd",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95f9c6ef-6bc1-50e1-b682-26411d64ad54",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f9ba62-5480-5534-a679-0f0270da8513",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a2c90f-ed60-563e-bb7f-b825a0898936",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61eea032-391a-5128-96fe-7f90dbdbf189",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2739cae-8e0c-5abf-bc63-30ad1bc47cc3",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0331872-1971-5974-976b-0c91ce849717",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43488a98-f77e-542a-ab3b-ff9e535a5352",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f718269-757c-50b7-806a-1f0bb007d21c",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67dd0b6-f4a4-5822-bffa-eed71abb6188",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31299767-e9f3-5025-8476-cbf0801a446a",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34dec06b-e8fc-51b3-b79d-1987797d8c6e",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c77ddf0-3cf2-5d8f-a464-6cc268b343de",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c405438-13ee-536b-927b-9386e541c2fa",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a31163be-9134-5163-9de9-61d1ea0e9988",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92802678-56c8-547f-a06e-0b731fde4fc4",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e25bfb1-24fd-521c-b113-c8ecde6a4d15",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8423015c-da07-5bef-a18a-8a54936fafcf",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.20-tuxcare.2 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@6.1.20-tuxcare.2"
    }
  ]
}