{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4bc284c8-a08e-53a0-b0c1-49e6a9486963",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "4.2.9.RELEASE-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ab790b6a-567b-5f44-929c-b1984d05b404",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3371601f-e081-5b63-b01d-5bb6109b878b",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff765321-f271-5065-9c01-bb007d634385",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-9878 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket. already_fixed \u2014 The target Spring Framework 4.2.9.RELEASE already contains the fix for CVE-2016-9878. The vulnerable path traversal issue in ResourceServlet.doInclude() has been mitigated by adding StringUtils.cleanPath() to normalize resource URLs before processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ee033bd-1947-5f01-bbb5-ed72ecc97e7c",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:442ebaec-eed2-528d-9228-f4a3df56baab",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1270 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7af10dbc-8922-53c7-811e-379a16596cf6",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f6bef53-6809-5b92-b262-6c29ee44a474",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31d5b2d4-774b-5507-8216-117c4fbcab23",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac8b5385-6a55-5402-92d3-9da7b0f0c978",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9cf2897-4747-512c-8da8-12716f5ad1c0",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ac0dcea-cc75-5cce-8cc7-499b8bbb6067",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05590fe-ad38-52f8-ac83-94f9d4223ed5",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c505e8f-af14-5089-bc42-cf78679baeac",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b727072-2db3-5fc8-906e-54ae9861d25f",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82fe6442-fd8e-592c-bce5-8380d9d83b4d",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83d8c62a-bcf3-5255-8698-179c0bf9d91a",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62c2067a-3a98-57de-89bb-26ab09d89885",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:316f264b-f7bd-5a8f-9b35-2189e14872ec",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43fe9755-9274-56e7-8b48-bd6662641600",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d7fa64a-6a62-58d0-96b7-4d97b586404e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64cc742f-1b44-5c43-9d5b-c8e83899739f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d7f8529-98bd-5f20-9e6e-5532059266af",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f5f53e-80bf-5ef9-bf76-b9044457981a",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4a6d26-af57-5083-a46b-335a7261a269",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38809 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket. No ReDoS vulnerability: ETAG_HEADER_VALUE_PATTERN regex is not used in this version (introduced in 4.3.30)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d81160e-76b5-5347-8a92-cfac21c3b601",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435e63fc-d108-537c-9a87-073ee1094a2c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a0a797a-f677-51b9-8572-8edde04a3696",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb0fcc17-1e3a-5a96-854c-c8304739faed",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa85389b-d3d8-5072-8af5-321df95a0b68",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8dcc764-a529-52db-87ff-8dc78ed22948",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:627c03e9-a7df-572b-8ea9-8ac5d6c906de",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956be097-91aa-50b5-8af1-917f60c7a946",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b2d017c-7135-5c02-a214-59d7e0d29872",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b738480b-7a36-5fbc-875e-5adf8bc37e95",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc801553-4848-55d6-a782-4f64046c7b2d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:904aeb69-6e04-56f8-b1ae-eb1506e23892",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dfddae2-6697-5d71-8cf9-bd7a44fdfcfb",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a39ba7ba-0a58-5519-893c-9e9e729251f0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb1716ae-a623-5531-b339-248172e37f1b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb51157b-b15f-5772-91ca-6072090a4cbc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db4ab89-0abf-5ade-bd03-f0b2d1df096d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb6c24b-0a92-5dcb-8e6c-a0bfbc78c1dc",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce1ddbb5-8d8b-521b-9bab-26b38e1afd8b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42f1dde-cd01-56e9-b7f3-d278297cc357",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afeb6e50-7d2a-5388-a270-c56001c18d41",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 4.2.9.RELEASE-tuxcare.3 is NOT AFFECTED by CVE-2026-41853. While the target version does process multipart requests, the specific vulnerable code path that enables multipart request smuggling appears to be tied to architectural changes introduced in Spring Framework 5.3.0+. The target version (4.2.9) predates these changes and uses a fundamentally different architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0b26c69-3421-571c-8d02-3aa01fbb1bd5",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02154b3a-0833-5c3f-94b6-6f71c4edda8d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 4.2.9.RELEASE-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@4.2.9.RELEASE-tuxcare.8"
    }
  ]
}