{
  "@id": "urn:uuid:ba72e95e-7fb6-4636-a6f7-bd4b971f24c4",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
      "vulnerability": {
        "name": "CVE-2016-1000027"
      },
      "action_statement": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2020-5397"
      },
      "action_statement": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed.",
      "vulnerability": {
        "name": "CVE-2020-5421"
      },
      "impact_statement": "Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-22060 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2021-22060"
      },
      "action_statement": "Vulnerability CVE-2021-22060 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.3."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-22096"
      },
      "impact_statement": "CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-22118"
      },
      "impact_statement": "Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2022-22950"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2022-22965"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2022-22968"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2022-22970"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2022-22971"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-20861 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2023-20861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2023-20863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-22243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-22259"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-22262"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-38808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-38809"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-38819"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-38820"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2024-38828"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2025-22233"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41242 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2025-41242"
      },
      "action_statement": "Vulnerability CVE-2025-41242 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2025-41249"
      },
      "action_statement": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-41254 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2025-41254"
      },
      "action_statement": "Vulnerability CVE-2025-41254 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-22735"
      },
      "action_statement": "Vulnerability CVE-2026-22735 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-22737"
      },
      "action_statement": "Vulnerability CVE-2026-22737 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22740"
      },
      "impact_statement": "CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22741 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-22741"
      },
      "action_statement": "Vulnerability CVE-2026-22741 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.6."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22745 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-22745"
      },
      "action_statement": "Vulnerability CVE-2026-22745 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41838 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.7.",
      "vulnerability": {
        "name": "CVE-2026-41838"
      },
      "action_statement": "Vulnerability CVE-2026-41838 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.7."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-41841"
      },
      "action_statement": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-41842"
      },
      "action_statement": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-41843"
      },
      "action_statement": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41844 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-41844"
      },
      "action_statement": "Vulnerability CVE-2026-41844 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.6."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41845 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-41845"
      },
      "action_statement": "Vulnerability CVE-2026-41845 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41846 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.7.",
      "vulnerability": {
        "name": "CVE-2026-41846"
      },
      "action_statement": "Vulnerability CVE-2026-41846 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.7."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-41848"
      },
      "action_statement": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.8.",
      "vulnerability": {
        "name": "CVE-2026-41849"
      },
      "action_statement": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.8."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-41850"
      },
      "action_statement": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-41851"
      },
      "action_statement": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41852 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-41852"
      },
      "action_statement": "Vulnerability CVE-2026-41852 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.6."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41853"
      },
      "impact_statement": "not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-41854"
      },
      "action_statement": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-41855"
      },
      "action_statement": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47884 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-47884"
      },
      "action_statement": "Vulnerability CVE-2026-47884 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-47886"
      },
      "action_statement": "Vulnerability CVE-2026-47886 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-47887"
      },
      "action_statement": "Vulnerability CVE-2026-47887 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59280 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-59280"
      },
      "action_statement": "Vulnerability CVE-2026-59280 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59281 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-59281"
      },
      "action_statement": "Vulnerability CVE-2026-59281 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging, and is fixed in 4.3.30.RELEASE-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-59282"
      },
      "action_statement": "Vulnerability CVE-2026-59282 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-59283"
      },
      "action_statement": "Vulnerability CVE-2026-59283 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework/spring-messaging@4.3.30.RELEASE-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging.",
      "vulnerability": {
        "name": "CVE-2026-59314"
      },
      "action_statement": "Vulnerability CVE-2026-59314 affects version 4.3.30.RELEASE-tuxcare.1 of org.springframework:spring-messaging."
    }
  ]
}
