{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:041be566-b02c-5da4-8087-87175b5d76b5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.30-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3d00e09e-f305-5d96-a8c5-51d213d5f518",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3facf8f-e5dd-5f30-bdd5-64f57bbb5b30",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63699177-2eea-529a-9d30-817b54f72771",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc6b8377-90d6-5c8a-bb9b-cffafb0365ab",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28d05fc7-778e-5027-925a-a99ac3e42cba",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6785198-1b76-5135-81f5-5ce002cdb2a7",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43ce2070-0729-51bd-bb4b-99ed9d426f44",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ec2d624-b23e-5f47-89b8-0ed01d473f0c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83cd89ad-6ad6-57a0-9b50-d35a96b9b555",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb41a727-2c64-5d19-91d4-39b386ffc6fb",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d351a33-52a3-523f-b8ac-53b2516cf6d9",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae87d9a5-e5f1-5a3a-8db4-dc89fe29f9c4",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f4f94ff-3c83-5bbc-9997-24a1913110e3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82420c03-54c3-5576-a5de-84d6b7e5db7d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1965e657-00a1-5e4a-9af0-152ddd9e4cc4",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8ddf9bf-ea16-578b-af7c-ce9c394fd21a",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb99d302-e004-52cc-ad80-696e09eea461",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ad867a-1d9e-509b-bdfa-c327797e6aef",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18f0cf64-1ada-51e4-a60b-55b982cd659d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03f7e846-6924-5b71-a38b-225cd8f62532",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8725b742-a5c4-54bf-8cc1-4f77fa71d056",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eba71591-afaf-5f29-8b59-cfb063cbc0fe",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.7 of org.springframework:spring-webflux. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54142b2-0fe4-5690-8237-7458c747fbfa",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f368bdf0-f912-5321-b7c0-fcbc8c1b1abd",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a41fd389-5211-5777-9238-c6cd887c1a59",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e567bac-57f8-54f0-9cbe-e4ed78a72c18",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d6d9d9-bdca-5b50-91d5-e251081eb3da",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84cc5b0b-4024-5cf6-adcd-5ead5e460927",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb9e13c-270e-552e-a63a-c691402b57b8",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94e591db-8283-52dd-a10f-3c67d5d59579",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f60a6f-f3b2-5e86-98c3-2d1f5877831f",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf891cf0-2740-5822-bae4-d3ae5bdde9d3",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e86f3843-2a17-5985-b529-7832cf53ffb6",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98e4187a-3cad-5151-bc5a-839592d63bf4",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f47aa38-c39b-5290-8599-ae87522b0bb8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bccce808-0d38-512d-bf59-c2225cce48aa",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:451f9fb3-0656-5fc2-8d1b-062f8e6d41ea",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7892edc5-c9b9-54c8-8897-cbbfaaa40d8d",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5783e738-12ee-5abd-835f-f7857726fc75",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6257b6bc-1867-5b3d-b25d-a34b8532570f",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c7a223e-2859-5a22-bf92-2567874ce3f1",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dec49e43-f87e-5767-8801-d72c6f63d449",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e600b9c-b9fb-5fe5-8d82-0d82f0a7f9ce",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f69fef-69a1-518f-abdb-3c5b752abe02",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1474a13-d0bc-58c6-8cef-a92bbf250068",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d506113b-f3b2-5f3d-85f8-fd71ed928a85",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fa0c2d2-7f05-5547-9246-8b8d7dd0e4a2",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68d28329-9e7a-5857-9eaf-766983b56157",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6d51e73-112b-50f2-aedb-ec21586a4c01",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e40f1f-4081-5af5-8a0f-833439fdf1f6",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.30-tuxcare.7 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.7"
    }
  ]
}