{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2654fab0-c884-5983-b4d8-ef5f96838bdf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.30-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1e75656e-3121-59bf-a802-591e8fad6428",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f02c38-568a-5aba-87d1-cd59c26b67d6",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21e57f3e-8cae-533a-a841-c3ecfb30bae5",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e1d444-8659-535e-a277-8766f8495287",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8554fce-02ec-52dd-a18c-b1869e64e064",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4d2b966-6c6e-559a-a489-589277fd9b18",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d843493f-edf4-5d4d-960a-289905732e8e",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef4718c-5773-5298-8115-8a4b2599d102",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e3664f-000e-5661-9c62-bc5f42fade68",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad09aa67-ad9d-5363-8b2b-b2c82f8907a7",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0188e1d-16ca-526a-9af7-98de73019399",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c0325f-8aff-5422-9150-6b77c3be0ba2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34cd0011-db18-5d9a-8302-d358169d9470",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c0167c-4958-5193-813d-2ac93403c2de",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f2e6d89-040a-54a3-a9a7-c3e15c3b878b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a6b1ef1-6d75-536c-9f84-f6796c5e68c7",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67891030-676d-5269-89c1-6cc1bbc27c82",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac4f9fd9-e106-5104-a238-4e8d6ce5ca47",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fd7d3fe-d7ad-5ce3-b4b6-8237095d95c1",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f844b4-6d8f-5861-983f-f4d6ea28db3f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5abff19e-e18e-50e4-8395-54b2b7c1e5fb",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b112fd-2cbc-5869-adf8-189dbe16ccc4",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.9 of org.springframework:spring-webflux. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f5ed5b5-b603-511c-b08d-2c0ad337b91c",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00683654-b94e-5821-b350-9768d40d8869",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99e757a9-106e-59bb-81d4-a98dbf65d849",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b988a0a7-9f5c-5278-9b98-690815e31870",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be769232-c68d-552f-97d5-4cdb7e8813d9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b59c4bad-0ce0-5a76-a982-d5a4aa25fb4b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ab16da0-ade3-5a6f-b53c-a8ad13b98c8b",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b94835-6448-53dc-8a99-6d2a13dee17b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad9a40b-5d49-5a28-b9ad-f6fa56e44e5a",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f4418cf-c863-587c-89cf-f53f309035e0",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba15a1e-87af-50b2-9d1f-10022485dae0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2661e5e-c519-5e4f-b85c-71d99e9bf098",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f330c8c0-f5cd-58df-bf8f-2f9eb476815c",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bebb2ffa-95bc-56ee-a79c-bd320b637325",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ddcf124-678b-53e0-abae-dd49a104a9cc",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74cd465-1078-5659-8a6d-fef44d75a98b",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c3da006-d646-5bef-aab5-e517295ba2a5",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b507d27-3166-569d-8a5c-83402dbb0301",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d87d56fc-4f7d-509c-9a29-350b8a7e38c0",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f471314-51dc-5cf6-a9b0-6f88b490bd01",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd3eb8ed-527c-50f2-aae9-8c16d5c24f6a",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f555b82-19f0-5bbf-b1cd-711f9f971634",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c14626f0-1dfb-5e1f-a5fc-6c446e662605",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4864be85-8e7b-5d63-a8b3-e13ecb6c4ae4",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a8f94e3-fe8a-533a-a5fa-05ddc80da4a6",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0d747b9-39d0-5dda-aee3-23832fcff8e2",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74a4514-ba57-53eb-8e81-8f1c3de477f2",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:468bf00c-78e1-5d0f-8075-a48632f7b1e8",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.30-tuxcare.9 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.9"
    }
  ]
}