{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:67ccde94-085f-5bbf-b2ad-bac6d8c6a6b3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1",
      "version": "5.3.19-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52dc6516-8b7e-5433-b29d-28d53f1c2972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8bed5fd-234d-5daa-85a0-a7d5a080f505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cbced80f-b7b6-5710-9b41-0053c7225844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:61caf67c-4477-5ba9-bd20-b80a70920617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80d45a50-d578-520b-a74f-304173abf750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3629b93b-126c-5177-ac49-0e8442dfe8b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b4c21aed-e09c-5661-9a4e-518072fefa35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd16ad28-d58b-533c-98fa-3fc9c3b8dbd5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79644fae-3b20-58ce-a47b-70e07b432ae2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4513dc1c-c27d-5d55-9874-d5559e43d68a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0ac1a57-f331-5eb0-a2cc-3091e5033760",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:decfe3bc-50f3-5066-83ab-bba79e039f72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56cc5ca2-9cd3-5b90-a4f7-43ff2005db47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55b28c81-f777-57f7-a467-2c93448c4649",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55bec67e-705e-50f2-91ea-b2cb49535f7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf336383-a187-56e5-ba75-e0fee62b874a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1c8c15fd-a912-5522-86e6-93c9690b9652",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a2bdef7-8979-5dd8-9b7b-1fdb2e081530",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d28f1bf6-7bb5-5bc1-8d5b-b07d171be27e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8b639f3-bb5e-5a91-b528-3769c1a0368a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36142e4a-ae91-5093-8245-0edfc3fe821e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b2b44aa2-ddf4-5b5c-9bca-9222a75f799f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d574b9aa-08e1-5869-9e8f-653b4f2eac60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:52921a5e-d44d-52a9-b389-e15f912d1872",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:661baa03-d47b-530e-a0cb-01654473e88d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f6c23c33-10b3-5b66-8baf-f6849097336c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f2892ea2-0505-50ac-923a-29df9fc50a14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b49907ff-3570-5298-a53d-e27f0bf53806",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c95aaa75-fbfd-595a-bde1-3569463b60df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:061b6b7b-c29a-5c54-9911-91128e481f14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:656647ff-76bd-5a2f-ada5-d7f58a9f8189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ba28ce4-5717-53ce-ab30-7c7f8de0cfc3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f7c37d2a-5842-5725-b6f8-1c9f4683bc34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd29e769-9654-564a-8162-f5d082f02f8d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.19-tuxcare.1 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.3.19 is not affected by CVE-2026-41847. The vulnerability (filter parameter shadowing in Kotlin Router DSL) was fixed upstream in April 2021 by contributor shindong.lee@riiid.co (commit 07ba95739b). This fix was included in Spring 5.3.19 when it was released in April 2022, over a year after the fix. TuxCare onboarded the already-fixed upstream version in September 2026. Both ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:542c831b-bbe6-5fd5-bf63-738dee654736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:562c083a-bbce-5851-9709-4ba287b3cc45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:21e4d5c3-5287-5298-92fb-956025e53658",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:edb41c20-3068-5e21-bc4f-e370f7a92299",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb716d92-62a2-5f1c-8092-270a5c56149c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a5e5280d-0f7c-51f2-ac5a-12237d815c73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4bb9c319-9723-55ce-8e6f-2c736ca68433",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53646fd1-c5ff-5250-ac0b-8aa536760377",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9344d34d-6baa-5c43-86bb-7074f899aa5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3cf5ad2a-25ed-5a9b-b5f1-434ad9fdb81d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4d86476c-9290-5eba-9450-ad446b2fe42f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3216cc2a-391a-5545-8590-c7dca63e8828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da42b62d-b46d-5e26-9552-5ad8a52d1442",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:439ee2af-c8f8-5d65-85fc-c89bfac8e6c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe752f96-2c40-55c7-99f8-2cb9308c8b28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f33a4aa0-b260-5a66-9c41-1437e7f0603d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da5ee0cf-5136-5214-b680-dd97eee0ce29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:22ae46b0-08bf-5a88-bce0-eeb2a6d6b648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ecee81ab-6767-5837-91a5-219a8c8b99f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9d47bbe6-a058-5718-a668-8f61847c236c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:443978a7-eb98-5b08-b1a0-af7d1c22bcbf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.19-tuxcare.1 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.19-tuxcare.1"
    }
  ]
}