{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b1798adc-02be-5ade-8e20-0270913c429f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2",
      "version": "5.3.20-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6586d59f-69ae-517c-a83a-8e785085dc2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2023-20860",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b6c3eed9-4ee6-57f4-8fdb-21c148a2f145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1bb63b1d-59f3-58d6-9119-8cca4d352fa8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58764894-c0ab-577d-9f1d-22850e0ecf8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a91d5d24-9d2b-566f-9695-2bc9d31a2d08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4eaac138-60d3-5863-9c66-be031a83c11b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:178ffd6f-1a70-5f48-a91e-0c588651083b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c575e25d-313f-5b13-b23b-7eb2f06e8cf0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f8488647-3106-53c7-ae93-05ddfb5acb5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b1d3945-8e6e-5035-8998-75c83f77b5ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fc83fac9-b7f7-52ef-8dbc-0ee5a08b752c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:02c9f154-488f-5ab8-9e38-f3f958e6de86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6aa06cbd-ff51-5273-8268-69ceb8eba47a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74f4d888-12f1-5786-9619-8ce4237c53d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b649971a-b3f7-5064-82c7-9efa741f886a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ff8b7f8c-5a81-5913-9978-0ccc02aab3bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d00efef7-01fa-5a6f-9e87-a2636cde9f08",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8ae8e632-82d6-5935-841b-ce51a84d7a48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76e179b5-8d7a-512f-97b0-ece36df2055e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b1d8c1d-14ff-51aa-a368-f74ebb7be0c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0a3c15ab-999c-5822-81bd-98934b3c0a91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:032053c9-46cc-57fc-8063-ac2ddd82267a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cf1c7e35-5297-54ed-99d1-b6153c37a21d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e6ac19e7-5869-5495-a90b-e9106bb53af7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f1fd8438-7237-5c3e-bd50-ffefbf88f6d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f01537e6-abc3-5964-9660-97220133a3bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:47cb3e24-9ed7-558c-a762-0fb4cef542cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ae724987-4839-56a8-ab75-ad3485cd6c58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c3bf8add-1e39-56f0-b7c4-7652d78c4ed2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:02daac57-4b36-563d-8a85-8276aa1bfe76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c81b999d-843a-5772-868c-cd16a03a89ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:08bd0768-9c67-50c9-910f-b0dbec952b26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32a28066-fbfd-5451-a870-dff80ecd1b2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c5be83f9-866b-5199-b06e-209e39d33e1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:07062ddf-4426-585d-b9db-ceec6bc4d353",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:754f36d3-132a-5bb0-ba0e-10b135e5b554",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:94e9cf37-ec5f-5bc2-8f2e-c71f092dc31a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e6b8e6b4-9b9a-5f61-9431-afc96d32428e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd183ae2-a429-55b1-86aa-558d2f969c1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:333c70bd-48f7-507c-90fd-08e980a8f8e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:42c889a2-44f8-567a-9941-70a3bbd1347e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2df9fdcd-18ad-5b04-8271-e375529a9768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5aafaa26-2174-53bd-8c50-a18aad25215d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d25e4151-626f-5db1-91e4-ab3db68ce476",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58ca5426-806a-5804-9232-10ccf7986034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2edfa733-42a8-5278-bb19-0357b7af3a05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da3b9520-d63b-5f33-a89d-09d5153b87cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:222361ea-c929-5b52-8cab-4987bb24d371",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2cea13a3-8a9c-5404-8441-27200f762405",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:29143610-4976-50ac-a821-2072a0b38c7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45a459d0-131f-56f6-878c-04d96b53d36d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:99515a1f-a146-5023-8681-6b3deccf466b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4cc77185-dd01-5d4a-b8d5-40feba75140e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.20-tuxcare.2 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.20-tuxcare.2"
    }
  ]
}