{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9f8df9b8-4614-5ae5-b8fa-f6e706075a29",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4",
      "version": "5.1.5.RELEASE-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9f2a9c1f-d31d-55a8-aee2-09fcd47e0196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8e66c914-0034-57ad-bc8a-28a75d822913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65d53984-650f-5cb0-a3ec-aa29bede1f41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b16ab18a-b44d-5072-8f77-bb88fa271edb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ef315b1b-74bf-5ad7-8694-f5d4656f8ea9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:63c63df6-9cb4-5160-9e5c-f06231c6bf51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f5058734-0aab-57f6-866a-7bdbcd7b5c55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:70e10847-cc0c-5e96-a343-b73f16d0a4a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3b433a28-ffe1-5cec-8e8c-65d637aab05b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:107142de-55ee-5044-b8d1-adc491483073",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bba8f2d0-92aa-5bec-8924-8782ecac317c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5bf549e5-f238-5b00-9464-85fad7f93aac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fd135950-d442-5a75-adab-5483a4dfee7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:acc6c6ef-549d-5274-8231-c804f19ccbc6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1f8e48bf-276a-502c-93a5-a643e2443278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c5190796-4980-511a-9cae-35a7bcadf25f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9c1ca134-16ee-533a-9e2d-f6a9d765ace5",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-websocket 5.1.5.RELEASE-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9aa4f9e7-fd81-5910-a6f9-6ddf02d8f71c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9669a5cc-7e58-57bf-a0d2-0776aab344d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:535966d8-bdd7-5d3a-b4e9-8cc5df366f99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fe9becbd-efc0-57de-87f5-c2913dd0b032",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0f596773-b196-5269-a7b4-907712f81401",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e9fa1c2c-57b2-50ab-ba38-30a6855d6a97",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c1256c0d-3a83-5c0b-bd67-15f3c21e0263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5a4bf25b-b9f9-5033-b803-276792ed9b02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d77b2a6d-b4c5-5953-a3ae-d40abc8aec73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:de658e5f-ea1e-5032-b313-dc3b2e4dad30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ebfa4622-5577-5cf2-b062-a3b1a75c1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ea9ee15c-3da3-54b6-a33b-55976680b790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1b26a051-7627-553c-a408-65f77511cbb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d2c93978-27bb-5af7-b051-baf043826ab6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a2ae8aca-859e-518d-8fc1-6796e8a09670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:782965fa-c327-5463-86f6-b391457cbe9a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c15c255e-3a71-5d0b-99be-815ac98c6291",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fca40854-2c6c-5764-83f8-e52167f11778",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:96b54200-4258-5330-aaab-9aaa201dc734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:526febbe-d23d-5ce2-a7df-dfb175ab363e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d632e136-4f99-524d-a55a-0f265f16e2b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:22cc1334-eb44-5890-8889-d645bfaff0d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5f9382f3-08af-5f9f-8c7f-cb00a6c261c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f085cdcc-547b-5bd3-a134-bbca64e9bdbc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:89293d22-29e5-54b9-8dae-4d2fdc0aaaec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a3b51082-af41-5d51-83d8-96948a545ccc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c91826ea-7fa8-5bbb-aa96-59da762a21c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:11ec2414-f852-5569-a5a7-fa20e03c4621",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:712767b3-6c80-531b-8747-3139054e51aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:74b8ab82-f866-5d11-95f0-f70261df2e55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e0599ea2-bc7c-56ca-9cc2-2ffbc0d2a43e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:23789e69-76ea-584b-8ea1-5b49f3366192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a89f5f39-a3dd-54d1-86d6-6458b3a7cd54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7d71889d-4d62-59b2-bc23-f315253a2696",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e00745a9-de2a-5a99-b4df-1fae078ba267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3385392e-9f1b-536c-9f8b-e0cc0ff5b968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b132755c-3776-5eda-9af7-b1589a797583",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8af8b244-16a0-50c1-88f4-c67715e368d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:676ac431-6216-5eb0-a16c-7890adcbb60b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c8079909-0d88-5c51-ba59-60e5069d9ef2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7efd7391-eb76-5ab1-886e-668b1257c410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:acda4962-8cbe-5b0c-8692-651e74ed336e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.1.5.RELEASE-tuxcare.4 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.4"
    }
  ]
}