{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0418f6d4-6fd7-5774-9862-6c106bbe35cd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11",
      "version": "6.1.20-tuxcare.11",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:b0a25f04-2dd0-5f25-a17a-988689aad94a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.11 of org.springframework:spring-websocket. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:374c3c99-23e2-5a9b-ac36-20fa6631b58b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:39bc7de1-8a25-597e-b044-fe31d9383408",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d63274ac-cdb1-5934-b0a5-2648c37410ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e3b4ac78-f205-5177-ac4e-71754eae1518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:4ab52613-4e3c-5e85-9851-f4f3c56b408b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c8025eb5-633d-57e3-8226-cbda68e0408e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:3c542d0f-e4b8-5560-92ef-0c8862e63b6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:745b2426-cbe3-57e2-85d2-d85a3cfea21b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f1c982c3-cf50-55bc-9929-a030d8756923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:203ce2ea-5eca-5240-9b0f-8dcb7c3f59e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:fa029751-19d2-56d9-9ad0-f9d764d70446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ed760211-fe89-529f-98be-dc258921f2c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a58dcb98-f126-5f4f-a0f5-b4a9690fe2ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:4f0e9cbf-a186-539f-be9f-be05896362f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ad7d4596-ea93-53c9-a876-21b953b57f35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:62c21394-e545-5420-b038-6543131ec13c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e8a2c16d-b466-5a6a-b984-f2fcc305f81e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:cdf749b6-9668-53e2-8e7d-b91503b5dd37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f1f5b3ab-25bb-5afa-8312-f3f109bfb3d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:9f89ae89-50cd-57f1-8676-9542fbc1a0e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e1d6c6a1-4f95-5be9-94bf-bd43121d6e92",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d250d3c9-9c4f-5334-a447-a96a98c9e637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c5fa8807-3b6e-52b6-b919-ee481a9c0477",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:4fd20db3-4fb6-58ff-80aa-88f419552629",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d9a2b5bf-0483-5ae2-aafb-59f7db38910e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:5492524b-5432-5aee-a4df-ddaed5285d71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47885",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d86752c1-67f7-5470-b879-7f512ef61690",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:798f5568-c4b7-50ad-935d-d63eb642ac53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:21e1633d-3121-5f22-aeaa-945abbf5ab69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:293f74eb-9f5b-55f1-bb8a-82daaa2fb03b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:aefe014e-4ca9-59ef-a45d-5a23113f10cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:6a1bc6b0-8436-5ad4-a7ca-2cde716ec5b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:dd613e9a-9d17-5bb5-9293-05aec6c4fc46",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f870d767-0076-52d4-9c9d-b0e1ee2d7c61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:b5a5926b-f923-5bf6-93b3-4c09fceb0d91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:52f9ed2f-6042-5540-93be-08158dc5383a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ee39513f-4479-5759-b701-49be80a576ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:42a88456-61a8-5ea4-863e-32699da5a5b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f3955b4d-db7d-51c6-b0f8-cb775edf850e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.1.20-tuxcare.11 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.11"
    }
  ]
}