{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cafd785b-cde6-5cc9-ad77-6729723f82fc",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10",
      "version": "5.3.25-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:dc5cd200-3a89-51ef-a728-15026954f8b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.25-tuxcare.10 of org.springframework:spring-websocket and will not be fixed. CVE-2016-1000027 is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e07cbcc8-9592-50c2-bca2-949e0ca06358",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ebc19955-62a0-5857-b0a4-548c46b496a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:fa32ee12-dbc6-56c8-a544-bfaf82af027a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:976985f1-3798-5448-b8cc-566f8a7bdc6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8467939d-d6c3-5a86-b60b-100aa2b50837",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7f558818-0313-5129-a81b-651a7fbb104a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b2f1798e-8704-599f-a629-776972e52fdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f4ec818e-995a-5520-98b1-59c28fa4c0fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:330726b4-7c1c-514c-a489-dc28cc2a242f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e1a47fa6-c14e-56bb-b0fb-0f0fbda9e3b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:1610b31f-c942-51d4-8d20-3ef0595e0617",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8ce8e469-7466-5fac-a804-42e9bf6cb223",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:25436bfb-189f-5504-b694-64fc729c2a3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2cca7fc1-fb40-5ad6-9d57-90b4fd2b46b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f0b948d0-730a-5845-b55b-85e37bc61946",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:140eb2ed-aeeb-5080-bead-ec7557105db3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:dec03d9b-bce7-54fe-8061-78cb2bd6490b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e8627867-0029-5eb2-a65e-6024bf93bb31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f342ceb3-f22d-5438-9ce7-d1cc75d2934a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f75c9084-5a10-5c36-a97e-9adda74af740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:038aac57-a10c-5b8c-9d0d-52464d2fd50e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:55a8abf9-4604-5979-87b1-c1e25e6795ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b728607b-9727-5b58-a299-f8fef7310f24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:78924513-d627-5845-b324-9e6ad0ec044e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:05791d8a-a82c-501c-b4a3-c51c7879033b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:adf3aa44-eb92-583a-843c-0a0a99e0186b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2d33a997-9395-5b15-a23c-5582e840b00e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:389b7bf7-fec5-574f-b669-7db50d4453c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d57f28a7-a319-523a-a44d-76b8ca815f9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:195cdc75-264b-564e-a5d2-08abce842763",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ce83aeb7-9e95-57b8-8aea-534051f01552",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.25-tuxcare.10 of org.springframework:spring-websocket. All 1 patch commits already exist in target branch",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b23e3fd8-f7f6-5bff-902f-bef6288f916d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:852dc980-9637-534b-8313-6536153bfbdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4c2d66e1-f806-5c08-ae61-057175f5371b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4142c22d-255f-5ba3-9d79-f542c638e713",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4a0ce0ec-0f69-5b23-85e7-a69ee8b41a67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:462f2e3d-45a1-54c3-92fa-dda908b4d027",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:64d100d6-f12c-5925-b993-0ba3ab01fb1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:66deec19-233e-5660-9d2f-dc169d63b3b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bb2f6a21-fc7c-5e3b-b382-a1693a9738d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:75bd4257-3730-5a5b-8818-82f052818ce9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4919721d-1d9f-5929-a8c9-4edac84266fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:67001a4b-ca0b-569c-83be-84ed70086dad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9c1e0523-9348-5d48-bb05-3819214a3c04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:0ef52463-7cec-57a5-a07c-2879e5d3b774",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d121afb7-f042-52c3-a6fd-0f952c7c65dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:433c567d-53f1-5dde-a0e3-1028489bbfbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:db14df1c-f39e-587a-8b1a-d6c0cdbc5ba2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:53c3eefd-97bc-513d-b3bc-ac7360db1965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e718e999-bd44-52c0-b710-deaea846b855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:639ab0c8-f015-53e7-8b28-322c7d940980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7c9f65fe-67f3-576b-a395-d4966ec0df99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.25-tuxcare.10 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.25-tuxcare.10"
    }
  ]
}