{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:69d0fccb-f51d-531b-987e-b8d34a130476",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.27-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:df710e9a-007b-55ea-82d8-d76a92d33a55",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89f95ea7-7dc8-54e8-8a27-782cbcff3bb5",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae2e608-8049-5beb-bc01-a22e180165f1",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb29b016-df7d-509a-8ae8-feb9bfdda749",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35bc79de-015c-5ea7-ae92-6c045e015529",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac669c1-36d3-5fa5-9f8c-153d04870887",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8066da0d-d0c7-5914-ab88-f1d32eaba7d4",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07041aa6-46ce-5501-995a-74569d50ba24",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e5f5e86-e7f8-56a8-93a6-22f64f87cf83",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:035b4236-7fa8-5291-8e4a-6fc13d9d0a5a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcc17800-917d-5b46-9eb7-c3d72ff7d3d0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe5763e5-ba2f-5652-a3ec-5d573e0dbcb3",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.27-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35bf5b71-a4d8-53c7-a14a-fc5baaec0f94",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66ccf17c-18c7-53d0-9342-aafaddeb638b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73cf1e14-9ade-55f7-b671-52d6aab315aa",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319e3247-3937-5b4e-b734-ac41194291c1",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5264f04-da1e-5276-a3b6-55165aae1890",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5318b72e-5bf3-5de5-87ab-4a39900e547e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a16f2c55-3a3b-50fb-b1d0-f7c6bb1627c9",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c368b208-ca3a-5f42-84b7-84d6a9b407f3",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9bd245c-8e75-5e0a-bd62-e8cd7a6533e9",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f418eac9-aabb-5ca0-b41e-336ae5d52188",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bd0b9f0-2ee4-5e29-80db-01fd86dc88bc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.9 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e0c92f-5a3a-5098-8003-7c211a227da2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64766f8-5e7d-5731-ac00-dcff1de39b23",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f86e2ba6-7ec5-5e58-a69a-ae030a7818ef",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17254a62-5603-5b6a-a0ea-d6663b7c9888",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd5836e-da48-5d37-9a10-8e723b893810",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37dc99ea-5f8a-5504-83aa-3a0211560daf",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aff7f33-ef8c-50f5-b794-52548caec644",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.9 of org.springframework:spring-webflux. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ab91d9-d2a7-5c16-ba11-78643034bcaf",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a739e052-b36a-527c-b825-8920b1b61bd1",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe15901e-c9f2-517b-b363-7d521eef1d82",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224bf823-1eb9-553b-a53d-9fb89465ca48",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6717d8b5-ea63-5676-9a8e-f27e949ef215",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c053a4aa-bd93-5baf-b8cc-744570956e92",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:752e56ac-6a52-547c-acd0-d9cbc22f7a6f",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74fa65b9-8e52-58c7-b5b1-feb515ce64f1",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19653a84-ed8a-5023-879f-fdf4781d066d",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a69cd767-1443-5e6d-a658-8f50030473a3",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c715337b-4278-5a39-957b-88388cacde03",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e726db8a-d7db-5bb6-a8c7-f5ed05f02a03",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60ad3f78-25d5-5bc8-a719-1adf77e4672e",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57453a20-ff89-50db-a665-7cbed2f81f5b",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9dbe3e2-b5d0-55de-a3de-629f562a40ae",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:752de995-8a7c-5684-97fa-c06f4c1f33ed",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4cbc8d6-0bdf-56b2-b073-c8a6099c2ecd",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc263f98-b91d-5428-8cda-a9aa9a85953d",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6150936b-edfe-550b-b908-fdb8b2073245",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cdda278-f246-570c-ae2f-035b87dfa3c1",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c2f7903-ef0f-5460-b966-e737eacf4863",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.27-tuxcare.9"
    }
  ]
}