{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f767f380-b969-59a9-9269-9296499badf1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2",
      "version": "5.2.7.RELEASE-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:55f21a2b-a9f2-51c2-b33b-70e706598270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0aee8dea-18f0-5e90-ac30-452d2c176cfe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f07277f3-14d9-53be-a9ae-30f236a82332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f7857395-e78d-5ecc-9f6f-16d620f4cb61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1202f6f4-5f2d-525c-8ccc-84dd74d92fe6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fb029ada-33cf-5bdc-9276-86770108bccc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c2abf89-8a43-545e-958b-230dadb3a972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f79f3c13-1a05-59de-95a6-0bc49e3ceac0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f98232e-02d9-5b0d-a995-9a35d85a9792",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:090e29bd-a8fa-5dad-8b6a-2204db979d1e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5efa1e0f-e649-54c5-ab1e-4e258fd93d7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a90109f6-d758-5899-be16-6ce749971064",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da89f966-e60d-5d27-9e8f-898575d93943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9f2dd2e4-f8d9-507a-b5f1-88de7cd787c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:db358482-39d7-5fc6-bb48-f879bb2e09de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2a706f1d-8021-53ac-91fc-2594d60d8c37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e65e264-764e-58c7-8185-2b45c245cbd1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:75c04d30-eee0-5d2c-bca6-e300a0caf06a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ffb6e2e4-2a79-51bd-a7a2-2f9be01b7fea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d489047c-355a-5997-b3fe-a0ae6586bbe8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.2.7.RELEASE is not affected by CVE-2024-38820. This CVE addresses a locale-dependent toLowerCase() issue introduced by the CVE-2022-22968 fix. The target version predates the CVE-2022-22968 fix and does not contain the vulnerable code pattern (toLowerCase() without Locale.ROOT in disallowedFields matching). The target uses case-sensitive field matching without any toLowerCase...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:40e5b95c-2108-5893-9b50-e1ee698c85d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b8774d0c-7d78-5224-b618-4b77d5df60f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7f76225-d40e-50d1-8cff-040afc453e62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:64df6a2f-2cf2-59fe-8722-8d2158217adf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3b54eb36-e476-563b-8675-71c35373142a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:01619ae8-bba2-5857-a251-d7ab5e5e6f28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:33b8e0d3-99ca-5fbe-b356-3cae3e738061",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7e72aad9-3d21-5e70-9ffa-ffabbad32967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c0a2703-81ec-5105-be5e-c53d8fb67002",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:539ca57a-a6d8-5dae-be73-9a51ad626fdf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:24b1dc20-4cc7-5765-9484-92ca7e184ed9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c917bde8-f3a6-545c-8616-f9211faddc73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0115f72d-7c09-5f58-a589-beb1db4085af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c8fbf44c-3214-548d-91cf-60768dd5545b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff0e185d-417b-5ec4-b65e-b49e283242a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:85d13219-09c2-54ea-ad7d-cad915fee5ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f50a6d54-ca97-551e-9589-66ac541c1b0d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b989434e-0b52-548c-9e72-a7ff6584fcad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3b364e30-b6d9-539d-8ab0-6868ff172530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dbc3081c-f223-5ccc-8a7c-4446b1f34f2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:64c32126-d323-5345-ae95-980cff672917",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74488248-ab41-51ee-802b-bc2238b326e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ae19d793-2057-59fb-945d-41b41f29698a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:eb759092-a540-5a31-ad3f-6574b6b7b4ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d464f562-52a0-58ab-b03f-da0aeb8cd659",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:64f58575-d35d-5027-b9cb-dbe67be20423",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:418e5d1c-ad71-5465-9a27-762a25add457",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e4ae42a0-0317-563f-9432-8f1d973fb3e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ee6ac64e-93ea-5e90-a2c0-7e8b729f46d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:46004148-0553-5f64-951b-0b0b05063ad2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1cc81110-9e7f-5c3b-8dfc-b6bb3cc64297",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5464bdee-a214-5baf-8489-426ada7b39eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f935512a-2705-5e80-a947-f9f260c1f157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9b56b638-a261-50ca-acc0-3e16b4730845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a3a9fa04-1ef3-5416-9cfe-f7ed748affb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7c3b4b6-f7ca-5017-a47c-96e31b2d7a34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a359e515-f4c2-555c-aa05-340faede8c02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0890157e-5e0b-505f-9196-c752a995664e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6e52b9e8-de89-551f-933f-7d82e480e236",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.7.RELEASE-tuxcare.2 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.2.7.RELEASE-tuxcare.2"
    }
  ]
}