{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe9ce549-e4e9-5c01-97ef-8c0a65de7200",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5",
      "version": "6.0.12-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-34053",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a68c54f8-fa47-595d-8ddf-d0d03fa9c1e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a4119eac-1d2f-5cb1-8c64-fe31dbead174",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:57a5f004-7384-5e73-a670-46567a79c208",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f494e28c-3148-5701-9624-ba991e5fce93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1b3984df-ac34-5f55-8905-bffe6f67f92e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b1ce1f32-515a-5421-9006-137607e2f146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5df5b6bc-35b3-5909-9ffd-2f6de48e41fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:86a4e5c6-7177-5edd-b99a-5de863693007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dd0a6da0-43c3-5798-97d0-952209280c67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8bd7eaec-6370-5094-a5c9-60615a77fc7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c410e387-906f-5304-b038-0668f52b115c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2cf0d82d-aca1-525a-9bca-2ee27a783c98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a81f49dd-1d07-501b-ab09-f3d3828f8985",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:652b1014-dbbb-569c-82cb-bf6e8014dbe3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2848936e-a90c-5cee-ab4d-dfe6c224e15e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:54e8b5c8-709d-53f6-b384-6f1c13e63b2b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5ef87a36-0a2f-51a0-b6c7-98d32038004e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3a2167b3-d09c-5ced-b74b-77b1b9a415c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f20a7156-b745-55fa-bafe-032d7a629557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:639905f9-d0b3-57b3-9e17-1f9b0fa1edd3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41839 does not affect version 6.0.12-tuxcare.5 of org.springframework:spring-websocket. Current version of spring-framework is not affected by CVE-2026-41839 according to the vendor - https://spring.io/security/cve-2026-41839",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c71f5a6d-084f-5c6f-9d5f-eecb1db38df6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8d48f1ab-bf4c-5d9e-8a58-898e2e39354e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0fa046ae-e0c3-56bf-8e22-b876d780db12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:22f1a1bb-bc74-52b8-a901-813f2b30553a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d90cd584-9b68-5bda-8d25-9cd69cd3505e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f929cb25-bf04-513d-93b1-66e662607791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2db971f2-8a82-57bf-b87c-6586c1aeb006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ab158147-c026-58d8-84b7-f43b3e53b95d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e7f6af29-0db7-55d5-bedd-8734f47ca541",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3f19bce7-c52f-5e7e-8b6d-d05d7c61b088",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eb0b27e1-fa91-5125-a601-0b719cdb7ea5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:692ba2ea-44db-5d33-b34a-4bfafd6090b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:550c2370-a7a1-54cd-abd6-0a03ba6895dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:de5ef838-703f-5fe4-b014-85a4c9159d97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2d4184eb-1f04-54ab-b2e0-4999e0d4962d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b463dc51-43e8-56fb-a8c2-75e8dcb15e78",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:28668240-2ea9-55b2-ad8c-cae25418736c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:05fb6727-2592-532d-b614-cb1227f8bc05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9565ea1b-ccd3-53b1-bbe1-cae844ddf0af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:44e7f3fa-400d-50af-87c6-71d1bbe1bffe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:21842061-63b3-5248-aebd-5e72c8a327e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d69af3be-d3f7-5bad-896d-696df6f4a7d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d53ba784-f432-5cc2-8249-f748ac71f8b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0735cb9c-bc64-574b-b552-a40c12167533",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1c0d694d-90dc-56b3-8bda-d98c54a3b732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3efd3917-afb0-5245-a901-3a3d8b6bc556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:adc5b932-4468-5bfc-8f52-7451a0766a04",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.12-tuxcare.5 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.5"
    }
  ]
}