{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5f30bc43-bfbe-5bad-b922-3145ab386269",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.30-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:000a01b9-66a5-5ec4-bf86-36ba0613b7e1",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9a3f56b-ba6d-5212-babc-90f1522c84cc",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543f802d-51e7-5342-809f-92a427392909",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ee90f3-5339-515b-80b1-ca5f0bf11e57",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d42990ab-8817-5f6a-9973-e9741b4f80b8",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c62c547-7ba5-501d-b769-e5e31c783467",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5851f85d-7ea2-5b68-93de-69b9c7b95c36",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:138e8773-fe70-5d8c-a1c4-607719bdfd05",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a3371f-cf2c-5909-bf1e-ab445600439f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d5665e-bfca-5c67-a53a-794d6ed837af",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a044cf9c-185c-5dd8-a334-971578b90933",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed98b9df-5639-59cb-865a-aba10ecdaa6f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc1449b9-b7f6-57dc-b77c-dcf6c6af6b7c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67749e9-85d8-510a-8ce2-1504121649c5",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29e31588-9c1a-5257-807c-f6e4b3bafe1f",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee356cf5-55be-51fe-89bc-ece29b7fa1b1",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aaf107b-e624-504b-b1c2-66688d2dcc46",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b788a8d-6d81-5dc3-9ecc-2aa9a24005f8",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f677022b-368d-55df-8761-1b9e3b17dc34",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c6e253-d60b-5278-a215-d51677c64088",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd6a56b3-2464-5bc1-997f-cfd8279d3a6e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2d6bfe-f4b0-5483-ba17-f2611b800c7c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.8 of org.springframework:spring-webflux. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb381406-811c-5bed-8f2a-b95fa43ce340",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51cb0db-3591-5ef4-9f2d-5959c1d25322",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c7041c-20bb-5ec2-8414-fcc3c827d682",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51b113a9-5a3e-535a-b001-7e5514284998",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47d191eb-c89b-50bc-9b53-2ec0e88a5811",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af8df8a7-6aac-5a0d-98b0-6b629d0d3c8e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01ea629e-f6c0-5500-a6d7-22106487d8f3",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2629ef29-93d9-5e69-9c04-85d0a417b70b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e99fc9c-a8e0-584f-850f-c48814acc05e",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cda18c65-af13-5810-8ebe-7952238d0ba7",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bdc05fb-9150-5b2d-bdb4-d06a9afc0ebd",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95409b65-65ca-56fe-87d3-6de1b7671837",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6010e1f-7ce3-5026-8598-688a71eb94d6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6d0c10-5b9c-5d23-8f36-85d42f7d2ebc",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffce2aae-265b-58b2-ad58-c2dc6a9d02c4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:744d378a-57d9-5024-8083-0a2c10d57b91",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e00b8644-cfef-5030-bbc5-012cbabbc116",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5335029-3d20-5239-af20-bde94d9070a6",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec90c7c7-75a8-5308-a701-412663d283a1",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec86f394-8f0b-5d2a-966f-e3ace1a02bd2",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:149685db-89cd-509f-954e-ad5497f858e8",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1d27702-343c-564d-bd40-e47623ea6c89",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d1bbf69-59b6-5f70-96a1-62582a0468d8",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134b2ebd-7029-5d8e-a8d5-ad2c19c24ef1",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2194b00-9ff2-57a2-a1a7-1206e1b1333c",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60a36174-2b67-5cc8-b112-3cf7c71e9763",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afaa8abb-4b10-5bda-858d-ddf476c74e3d",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e22a3624-eef0-5794-a551-b67caa38c64c",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.30-tuxcare.8 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.30-tuxcare.8"
    }
  ]
}