{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7cfc906-320c-52d2-999d-e51d0f38fec4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-webflux",
      "version": "5.3.31-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ac67da51-a5a6-5146-83aa-cde9010197c7",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c216be5-7cf4-5de5-a356-ebe8a95406aa",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef4dcf67-fa6c-5387-9d84-e84aa8970194",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4359d3f2-9505-58f5-8856-e22e8bf1da83",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4d918fe-095b-59ed-8d93-fa5823428623",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ebb2e5a-cc72-56e6-badc-4a016196d8bb",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f3b7a2-c2d0-5a9a-abf2-a5f12bd387e0",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e90a87e-6150-50f1-8187-22f22e88a796",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9ce1d70-45db-51f9-a2f7-4180e8684e8b",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dc191d8-e3ba-593e-bbc8-e139ca3116b5",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b6dab5a-0334-5901-aafc-14ce8dd3ed99",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e73acc31-5127-5546-824a-6db68e8fffcc",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-webflux 5.3.31-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bf01bab-db0a-5aa3-a4ec-e38c482482a5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:275bd251-0c67-5e60-b918-0c6d1bbef645",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4698700-9fdf-5f95-b60a-f724b4fb9706",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fee3c416-e53b-5703-92a5-a133243464e0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd359e4c-fb8c-5ffc-8026-9a6ea94876ec",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab57240-3bb1-5e52-adc5-3acf0b6ebb8a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:301e1865-7334-5b09-a242-23faf74d97a1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944247bf-aaa2-55d0-8786-ceff346c6679",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2196aeaf-7b92-519a-b6f9-97dc7a1f436b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1732c6bd-b1bf-5638-8249-1af23d162c9b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e833dc4-c582-51b3-8e8b-c13fc71707b5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.12 of org.springframework:spring-webflux. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46987b2f-c355-587d-b936-d033f0ee6e96",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c64102f-f840-5bea-96aa-ca9f30ac35a2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce2cbdc-5d8b-54e6-b1b0-f5d6dc2e01d9",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fb8656f-e5f1-5b7a-a403-7cab122bd083",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a85cd3e-c328-5735-ae63-8373a143dda9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77874be8-721b-5bc4-914c-620abbb6073c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1be803e-789d-5def-8392-8ca308d1c709",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b1d8258-dafc-5af2-8fb0-5d15fed5882d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d95b21f6-b556-5ba3-9c56-fde248bbd317",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec626b25-43bf-5a17-94eb-9f4c5a829c4e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff969c1-689c-5523-8690-e367ef74afb1",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f392991-ef46-55e7-95ce-468adad5efd8",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f96d036-f8db-535e-a1a5-a3ca14834784",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a35fe2f-0470-5196-9002-da5b61dfcf5d",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3212dfdc-e43f-5a72-af0c-51a715955e47",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d8279f-1ec2-56a9-9c20-f82260790dae",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d174c7f-0ba0-5b4f-b637-4ebe651c7f56",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf53117-76c3-5eb5-98c7-4397be679622",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cacca0c4-8921-511f-b673-069ec680fce0",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2746acf-39b5-51d6-aeff-161714cf33a9",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efdcc093-f84e-52b7-8173-aeac599e0b6c",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eedaa91-2929-5613-8014-baff63c97469",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a027f09f-0155-565f-a7f0-5dec484f5f4b",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35449120-2851-5165-8ea2-e6c768ad3f04",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab808421-6a19-5e20-a89e-da3c33dea970",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43e425df-1dc5-5497-b697-0f86f6af8fc7",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b87902-c911-5da1-acd8-d3f4f38fbb1c",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0d506c-fb4f-5224-97bd-dbd41729fe0f",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.31-tuxcare.12 of org.springframework:spring-webflux."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-webflux@5.3.31-tuxcare.12"
    }
  ]
}