{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4646b313-3695-5ea2-901b-63f173f5f418",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9",
      "version": "5.3.24-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:76a24275-969c-5e35-8c45-1e4d139804ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.9 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3d742004-6f3f-5dbf-96ba-2914befc92a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fb4b3212-8409-5f83-badc-67b0cac57a01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:98a27ed4-40cf-5e23-9509-fa070bf8a985",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2076dd73-fc69-560b-ac45-ec2d24d904f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a3527f1c-01d8-516c-bb3a-7bb73689e3a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:40b7c788-e7f9-5551-bc96-8c7fd2a6b5db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bb3c0317-1a54-5dd4-91f1-e62fbd2fb1ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:769261e8-3297-5d1c-9c13-5ef0ca9b3167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:944c6ede-a9a1-598a-9333-49d2b93adb4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4cb2348a-644a-5a41-b173-77e1eefb14a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:38b308a3-5b5f-539c-99c1-361e648af235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7ca722a1-52ea-5569-b389-554d4f45952a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7bafbdcf-ca02-5bea-a4f4-3ff6f2ec912b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cb7860e8-1111-5537-9967-123c2bf61573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f29f0fe0-b79c-508f-b4cf-cb6b5e156f18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dc9a7b15-fbc1-591e-a853-de5e9fc0ced0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c1c4a99c-8bea-5e0b-acdc-62a99796cc2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1da6140d-0a11-588f-9781-6fe2c174491b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5347d1fd-b636-5794-8acf-10b21f4f4cf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bbdab902-d57c-5050-8976-f590d775915f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:433b691e-c637-5173-834e-a7105e4c1a2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:210ea932-cf90-593a-87e9-bf3bdc5c0fd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e7c86985-86fc-5927-ab66-c0799679ec9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:605415c0-e33c-5c5b-9b4f-7af5b9084d62",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.9 of org.springframework:spring-websocket. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:89f82152-82f6-5c4d-b740-b5309308bc42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bbef49d4-be78-5eef-8bc3-9d3d88450cfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c51209c8-7250-561e-9def-679c0373af5b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:185e7588-2020-56de-b4ed-d39182ca0a90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9951fd42-da27-5cab-8689-d70f7007f178",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a9afe849-0071-5cc8-a743-7f6f8b6335d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b4b0bbd1-cd4e-5b1c-ba0c-9ddda37949ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:286e9452-cc93-59ba-9a2e-635f9d35f2ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5ade459f-c66a-5f79-9601-607f66bd930f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:be365836-df3b-57b2-8021-80739358a745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2b02059c-8390-5c23-8757-f1db2ab31536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cc8e6d5f-fa86-5694-a2aa-e35310a77d7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f90410ca-422b-5d49-9bbf-bc6399c3de38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:02f6d4d3-0fa9-52af-8868-ccae90c00c1b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:babefeef-c815-5018-8d04-e83e4eb24d4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ba3ebcc3-effa-5174-8547-8a1dc9b972d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:96f84d21-4f82-528e-922e-575e6212b292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ff51ce91-1561-5185-93b6-f4ab6e11dfaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fcb960cd-fdb6-5237-a75f-ef1855bde93e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:02811119-03e3-519b-b3c0-d5af8958c7e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1efc3c0d-e4b1-56d8-858a-2dbfa1c9c1ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:66a4b031-1cff-529b-905e-54368a59c808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6205ae5f-0c23-5788-a1db-3f85476b61e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2134405b-5a4d-57e7-8cc8-adf4e988153d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f5d41fef-654d-5b41-826e-a301ebb8200c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d163b330-ccbe-5d2d-909e-090b8b232c53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f9f3a30c-eb0c-5cbb-ab32-0d5e38507c9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8c5a77a0-9738-5d20-87eb-6713d16a4852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.24-tuxcare.9 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.9"
    }
  ]
}