{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:84582d03-3a14-57c7-853f-f20ed77eb4a0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.31-tuxcare.11",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:75d08f93-e861-523a-a7a9-32db142c5bf1",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef86a803-cc7b-5a0e-b855-bf1f0bbcd16d",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b49f08-4717-5c5b-b634-21067b9d2a9c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc9bd07-dd0e-555e-be4b-28fd2ec02c18",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a6cfd21-e7ca-5b56-bb6b-06c3055b1120",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecf85ef5-1d2f-5c64-9ca9-0e3bf8710eb6",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b50330b-d0f7-58ff-92ad-7454c48b1bf9",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4712026-0c86-5f4b-8a8e-1f340f14f092",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:983fc711-e3b0-53a6-95b4-cfa0478fc1aa",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cf3b4b5-3174-546a-a238-21350208ddfa",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c13f0b54-6a97-56aa-8586-d7d5d0519ff6",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935727d4-53d9-552a-af1c-3281ee31a916",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.31-tuxcare.11."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf8f6b5-9faa-5332-8c06-01257f9ae25d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc7ecae4-bedd-5a7c-9df2-2ecc2e04017a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d581d693-f924-5fe7-9aba-2b1eaf9e4220",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89fbcb4b-3e5a-540b-b293-53bb96384340",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:229a9e16-52bc-5a65-9115-7e7a66b7ecc8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aae96fc3-aec0-5ae9-8db2-ec94982185fc",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d604c2d1-3579-59ca-a812-8195d9d1dd28",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92f05576-e50c-5042-b077-91d6b489a1a5",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d76c7e77-0300-5a23-b2cb-112a628b3d6a",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5431918f-1607-5f4b-a701-77b86e0509d5",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7552606d-1434-5dde-836a-1edb7a17ce0d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.11 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3577f00-999e-5970-aac7-3726f82157f6",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c10bbee-b336-54f8-9235-315bc12d0d05",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d678489-8485-54f5-9be8-dba7bf528d24",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feec0c24-300b-52ec-b57b-0bbc4b9bcf7b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f82749c-ed17-5b3e-9f4b-433fc27f2811",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f68ad9f-11e6-586b-8087-f31cfb364df8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b337f083-4eab-5585-bd03-81106a1cc752",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f65135-a56f-5b24-9d07-35b7b19cb2d7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:949aebb2-a9cd-5878-b01a-48c339dbd92d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b2ab37-0bf1-56aa-878d-61f566695d45",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a75a57-b950-52a0-adfe-d427faddcb5a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d87206bc-646e-5a88-829b-851ce1d91f92",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675b55d9-cf82-5fc2-98e9-6608cfd74bd8",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5184ea0-4a7c-59cd-b9a9-ee9d3d6e274b",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfd02f25-8cf2-57d2-b374-5164bed96510",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d6ef05e-b201-5e6c-a0ac-f0fcee4a1956",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c185a01-f254-55a3-8cea-fc53b236f98a",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b765437-06c8-591d-a83f-f739e3a78900",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c7e5234-dbf1-5e2e-b4d8-7834fa27a785",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89747410-a2aa-507c-ae34-9d1738366f24",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c44f95dc-985c-51e3-bc27-65ef4114c37f",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db21ca5-894b-50b7-874f-2d9647d88e7a",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285d6dfb-a20e-5055-91c2-6d1b2841d8c1",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2832fe5e-7ec7-51e8-bd56-04aea92773ed",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d53c36b0-33ca-5fb3-a21f-a21c831c539f",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e53929-b7e7-548e-aae8-e7028ab6b209",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90994cde-21f9-545a-8737-8d1719e7475f",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1ee1651-ab94-5831-bce7-e60503bb0109",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.31-tuxcare.11 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.11"
    }
  ]
}