{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b8b93778-0402-5757-8acf-7ab930d57469",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2",
      "version": "5.3.6-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5bc7e7c9-c50c-5ea9-b7c2-24440354a139",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:884e2200-bf82-511d-a8fd-a678cac733c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:65158c48-364e-585d-98fc-e321ec70153f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:abeae1da-0abf-586f-b76d-6cd127740b68",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f0ece147-b1e6-513f-bab4-5d04703896a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8bb75984-f96f-540c-97b6-f2105186ffa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d07e38d-a28b-5967-a703-9ebf3722c3fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:50405caa-9f06-516c-9767-a33a3a991ec7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f9468ba1-ad24-56cb-b70c-b17e596a74c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:72e33726-8c3d-5f7e-a2d3-64243b83d14e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9909f994-2233-5ff9-9081-092fa71e9a78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0c5765fa-af9c-5710-8917-2f929eb71b47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:49538337-f376-5130-84a2-0f800a474241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8762adc3-1229-5760-a903-98ca059d5cd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aedb727a-1349-5691-ae3d-88accea27f57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9c0878b3-5f7f-52ab-94ba-f1694e1d3543",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1da80296-9adb-5337-beb4-b9619c3afcad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:90f7500e-7b06-5cf4-ab8c-c4e2c3a9dd21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:900b2729-9971-56b0-9c16-96f12664e1cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8492136-8f31-5c89-92aa-84ccfd41551c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.3.6-tuxcare.2 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.3.6 is not affected by CVE-2024-38820. The vulnerability concerns locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, which was introduced by the CVE-2022-22968 fix in version 5.3.7. Version 5.3.6 predates this fix and performs case-sensitive field name matching only, without any toLowerCase() calls in the affected code paths.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0597c2af-d749-531e-b1ee-a16403192639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cde8a5da-b3f7-522a-b7ec-f37fbee9ec64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da5cfad8-6a21-5b15-a7ca-018f2f2bb653",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58ffc36d-34d7-57c6-ab71-503f656bd4b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:670e0233-0e86-5888-b96e-2c5037664bf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:541b9a9e-3214-53bd-854a-e37e88810024",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:05ee8492-7366-566b-a199-80cb1b0e3f2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f02564f5-0314-5e7c-8fbd-aa96a32c9660",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d797d6c-cc4f-5038-ae1a-c7bd38955c92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b73288f5-ea48-55d9-9323-fa018ff77b41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d2158d52-1a70-5c4e-8b3b-80983b457526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:48ff732b-27c9-5e62-986c-97e270f44bdc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:75ee019b-1844-5dfa-b561-68e29a853134",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a15273eb-374e-51d7-b400-40d361f54377",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e6d81e1-7769-5f2e-89cb-0bea09c53d69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e2cdce99-4e90-5443-aac0-30f791bcac24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9acf866b-e307-51e1-808e-20061a59bc22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:12da7cbb-26a3-5adf-b9e9-73460b29a0b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0afd41f-de94-5a3a-bea1-4a14eecf0228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:715ef010-60d0-567d-92a1-e3850323d47e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b432604c-2e13-552e-b75d-bbd4476187e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9179f733-6e2c-5a9b-bf57-ea61a78c5042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7b254bb-07f0-5d21-9530-3cd3d796316b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1d6f9df8-692f-58dc-a5be-86b548fcd69e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43a2b3d0-e719-5413-b740-e4240a5d280f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9061de27-262f-5b5b-ab78-ce20cb3347d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:71ebcfb4-2916-5192-9b0d-2517d8a2309b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c2d30923-5e8a-5cac-82d9-ff65373e2113",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aef36e21-b5fd-5d67-99d8-d377487103ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c24b8e4f-7b8e-5b90-95bd-02e4e17c4a76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4b135a0a-33a5-5d43-8b5b-7345634b7481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:89613000-3be3-5250-b5ee-7ca0736924f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:705183b9-44ab-5086-abdd-bc2d77e18202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dec8d1d4-1f7c-53de-8739-d5a43ddeb835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:23a6f9c5-5bad-590b-8f8e-3b7f63172b42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:911f2b72-cbaa-5066-815d-2728bdf7e39d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b20df2f-9999-57c0-8ea9-a2820dfdfcfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6fe16778-0d10-5469-a502-5c9109f03e3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3168e5a8-7738-50d7-ad8e-e768df985a8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a56cac93-75f1-5487-92e4-cbc315e1b4b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9b1f03bb-7d23-548e-a21f-c595ad3bb44e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.6-tuxcare.2 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.6-tuxcare.2"
    }
  ]
}