{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8cf79f5d-4593-5555-8895-846bfde36870",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4",
      "version": "6.0.0-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3d3de7eb-8bae-58b8-bb76-8f91d640451e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:776985b0-ee1e-5b20-ae6e-5ef0f08a3dce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-34053",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6688eaa0-91b0-5e18-a5cb-f8693e10c4e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:23c4e07e-7c11-58dd-a4f0-2f6dedc2fc8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:64ad2c38-aac6-5085-b01c-574910d28994",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:90235496-f200-510e-9293-f0e80c7450c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7764187e-6c4b-5524-b533-fbdd299e5919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:edf31b61-5519-5c38-a2ad-9ffcfe013671",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:da201561-ac02-5db0-9c1a-2e48c2961d8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3baf6555-7682-56dc-85d3-cc632f813589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0cc7c54f-42a2-5b09-a636-82e309aa71d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7212a8dd-84bb-5394-bdbf-f8fa7dd950bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1cf5c390-66fc-542b-9719-08f7609a6648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aa06478a-f9ad-5f42-8f1e-f8450f0353e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d733e916-1bcb-59aa-9d3d-f584c6bb3dc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:364c7d8a-1a68-56c2-95fe-af33d8d61259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:999084bf-13b2-55ad-8e55-5c0dd2bcf1d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a9c49a44-69a0-5df2-bf5a-41a65fd2dba8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:98c61f27-f0ae-54c0-81cb-584b6c9f322d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:86d999ed-9ebc-5e6d-895d-7eaeeb147eac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ffb769ab-a25d-56a9-a2dd-8a14ed4ca9ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:826176e6-ecd6-5d55-bccc-fa5246e5d0e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8f02cd19-ed72-59b6-803b-02c0b276dfcb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5a279ff7-353f-5936-a454-d573b79021fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dff057c0-0f53-5f0b-9d9b-78481b1f7df9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4e5153da-50e5-5fb0-8590-822ec185dfaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1cad5b1a-71d7-5a1e-92c1-69cdf254ae58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bb87ff54-d0b2-5b5a-bb7c-c7b01bf1c4b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2d340749-1b94-556f-af39-0a1618f1ba83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:57ba81f7-8626-588a-8e43-0c68aaea3a48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f251e97a-a180-5233-ac3a-0491568dbbd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6a1b722f-0e67-5732-8068-701a3476c0d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d5f4d52f-4a3f-5f45-9f90-49217232b747",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:324265db-1dbd-5309-b361-8353e1002f2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fc035187-09d8-58d0-8ff6-cff49cf75f39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:08a0948d-64db-5b62-901b-6ced042cdadb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ff7f0bcc-dc73-56fe-9dc5-36a1700ba7d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:62b4db77-784f-564d-8da0-d66dcb632f6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8783e16b-641c-5fa6-afde-6a3683aeae95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:caf500e2-02d4-5813-b2d8-c314b3157b28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:89597247-84c0-5181-8760-4414bddaa3e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:41d44a1f-dbd9-524e-833d-3250139b49ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9e50ee89-56cd-5f3d-8715-aec74f4e58a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:889ecd11-511c-58ce-8170-0974b755a5fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:26b48349-2c4a-5cdc-80ab-44811a381ead",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b9e25072-5323-58de-adbd-0bee716582cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ba5d017e-3a7e-558c-b170-62afe6d5051b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6a04ef95-e8f6-5dd4-8d09-a30a1ce62bbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.0-tuxcare.4 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.0.0-tuxcare.4"
    }
  ]
}