{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f7ee28f7-d0e1-5974-9b79-e989c38b36d3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "4.3.30.RELEASE-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ae756f46-0cff-59f5-bb64-ccdf1573f648",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12467ef8-a25d-5bf7-90c3-5beb0ff0c9c3",
      "id": "CVE-2020-5397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d64281-54bb-5f2b-81e1-2590171ace0f",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e08c210-5d52-57eb-8810-ea19a311f63b",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:804bcb6f-3d24-5bd0-8fa5-a58612537402",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f57c39c-f0a2-585a-bf0c-0774b98cb30d",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2428653e-9418-5d4b-8712-d23ab9cea5af",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a9e4f4-bac2-5833-a8ce-3579f743b519",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ae256c8-8d08-5ecf-844a-e8f045385e9a",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e256b08-9b9a-55eb-ae18-9e44f287095c",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0b08869-d352-5786-ae0f-ac0066c7ac20",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52e472e2-befe-5565-999b-17268c9ae64d",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7580520d-836a-507a-bf88-c96483139337",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4402b54-d040-52e8-9569-e37519aa3b59",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b1c9b27-218b-5a14-bed7-4b67aebab556",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:576dc76a-97dd-511f-84fb-2d3935488a86",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:276b3713-3549-5c12-9489-fbc18cc45b93",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a295ff-812e-5cd6-94ef-f9f12bb13050",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:398551f3-366c-5bed-9550-b0ef45d5fb61",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06d22067-7616-5ad9-b673-3cc1fd9aad3f",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2119353c-1ac5-5113-9e02-8cc669d41af1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3c6a7b7-91f2-54f6-81f7-8f217ba14439",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a66f66c-22c4-5147-b30a-815df2362e6f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:940e6943-09a6-5c16-9e2d-3f0c48608539",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfcf7546-8545-5aca-8372-8f32b23cd761",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a265b32-1c53-5a1f-9868-057e2c96ad16",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf888249-c8f4-5189-ab21-687d094403c1",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddc0f7c-86fe-5bc3-a571-19330285a4fd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e1063c6-05d2-5c5c-8e88-5b21e36a99ce",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d407b2-a055-59c2-8b45-63d4e245c356",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f9aa79f-71c2-5ca9-824e-f3fddea262bb",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f39e98a-0209-5055-a6e4-baa89132447b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f953942e-969b-502f-aa4a-d158c52474f1",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28d9233d-e00d-50f1-8578-824773754e6a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc649c00-77d4-5fba-93c7-f1ad91f0998a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9777c07-c579-544b-a3a2-56cd14062fd8",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b3998ec-e96e-5b85-a0ad-b3dfe68bd997",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75ea17f-ae5c-546a-9c21-b137a180fe9a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb48eee2-b34c-5ea5-9bc9-9356a3e8c700",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09210700-6e9c-5554-9fa1-66cb72f22b85",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b88f6a5-53ce-516a-9785-f8764a3fa365",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45a32610-32d4-5281-ba6f-a03c28476ab7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@4.3.30.RELEASE-tuxcare.6"
    }
  ]
}