{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:599951e7-3bb1-5ea2-b7d6-b1a67fd84e79",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.24-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bc4304a1-e7b7-53c4-9c46-bf0500200f91",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b86db815-0677-5742-ae85-e536464d3abb",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1871dc1-c2fe-554e-b510-5d36c2f4e0ab",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0938c197-5502-584a-8c02-8a973553cfe3",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9118e68-15d2-5a99-a71f-f788bd8fff44",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c97e47d-4910-5227-ad12-f1a80a221c8d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:279d88e1-9df5-5767-b22e-677c1b17b59f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f73e78b-2d28-55f7-a184-7c160a45cf90",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:570e1bbd-c720-578e-8424-457fc95acdc1",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1537c6f-d878-57a5-8b8e-bcbbad255271",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:974ed24b-76fa-5295-9703-d3d58729faf8",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f21b9ccb-3e59-56df-a78b-f7e6d47c09af",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f6cac5c-3734-562c-b659-08ffcd81e37a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c40d7e-c35d-5398-a67d-d5dd9081a49d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f10bc63e-54bd-5c11-9d44-f7d29274ae25",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b67dbf5-6794-5415-ab49-c2a8e118ca71",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:199dd42c-07c2-5551-bd2b-26d574099bbb",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39630e0b-2f6b-5946-a181-18a7b801b912",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d78ba51-c0a6-5d6e-b571-595a2e0f706e",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d50d9253-7646-5132-ab1a-3e00d501c16d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3e283ff-1c2b-51cf-8019-9d532483294c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6a1686d-f5e0-58a7-b512-c0a3f093308c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f10aba-0c69-5253-b1d8-7844ec08bbde",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:238a7263-f50a-5c8d-9cfd-63f9d90fdc9a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06aac2f-3495-5fff-9ae1-c63ae15fe5a8",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.5 of org.springframework:spring-websocket. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42b6f374-7019-5e2f-9fe3-140a1a910738",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a333bf36-9b70-5857-8cc5-718effbf5f8f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93fab289-214c-5e01-9d03-468b8fc6388c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ca22e46-28be-5d52-ac6a-c7759121acbc",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5df4a721-dcb5-51b0-839f-a5c76ae208c0",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21b5444f-23a2-54e8-9d70-4bb5552c88d8",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e4a407-ea78-5e0e-a0fc-46bbe75e5837",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:897d6cd2-640d-58fc-b4fa-83a1ee78654e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d918dcd1-0675-530d-84d3-b9ac9dc41617",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b49fdb1-492f-572a-a14e-59d5ce1e7c3f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eba1ce9-43a9-5f4a-81a4-8184110e8642",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4b82e2-b9fe-59b7-ae13-99f20a807ed8",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611e9244-812e-55b1-af73-56ec0c57f9c6",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1cf22d7-7b0e-5ac9-a4e3-8e38089a9c60",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d39437f0-4c24-5ef0-b4d5-01dd2666f717",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.24-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.5"
    }
  ]
}