{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:abb620a9-5658-5376-b713-6c690ab5a66d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.27-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:25920366-1eda-5569-b785-a37ff017dcbf",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8aff571-3e27-52f5-8769-a448dbe16ba3",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ded525a-8f8d-55a3-8fa3-ff1cbc86798a",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1926f96-ed78-5be7-acf4-371e9ae0413a",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3d1409-4bf8-5180-b34e-12d891d46e44",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c7d739-b699-51e3-a865-aec3d365128b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08d76678-546b-5cef-8478-809f2d8d4643",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4c90e4-bc20-5124-98b7-43e80e99b338",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0debd2-a3e1-5a49-a531-42478cd31781",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae18cb6b-5bcd-5465-801b-dd9a4cb51fe1",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca11a651-fe3c-59d0-8628-02c8f60f91d1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac3f6f0-a598-5d45-a2f9-6c4a7a12cff3",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.27-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3636902a-1f0f-5535-a326-13478073c339",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb8d2fc-5657-5d28-b370-a5f80abac2df",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d10220-597d-5e4b-9cb0-bd35927885f3",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c21c1722-a499-5aed-8779-391e512633ef",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58df1d68-66a1-54c2-ad8b-4d1a9cb781d4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c99a43a-c501-51cc-a4fa-3ff2da17d88f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a40abe0-8a52-571b-a1cd-e0c015ed4fbf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a075255-7e18-501e-b054-add22b866583",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a30796ba-68b0-5c6b-a6c4-fb854d954404",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db83b16a-053d-51c2-bff7-243f7d6904d0",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed848e1-86c8-5cc5-884d-6cbaf12a282f",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cff9956-7efb-5708-94ca-24a03d73e1c6",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a295d98d-eb1e-5dec-8751-3cc7a1dd5f23",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f496cee0-8e60-5143-936f-8b88e9f250f5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b2bc45-9132-571b-b1cb-f829a157df8e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff74d249-b742-5513-aaa7-e2cceede09a4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9838812a-51fe-5ea2-86ad-38df28d773b4",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c8da85-d88a-52fd-9895-743a7b039c62",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.7 of org.springframework:spring-websocket. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cdcffbe-75cd-57a5-9431-35f01657013f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d3bb650-b421-5321-a0a0-004940a7970f",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b9165d-7722-5ced-a171-9aaeccce742e",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47538745-35db-5284-b729-3823fdc3357c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18ce59da-74b7-58d7-a847-0c17eae2bdcf",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a588f50-00be-52a0-b1fd-9ba404d7c972",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afd78f3f-58b0-5749-9226-4a10cc285854",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b93b2b-ed87-5a77-b76b-0c660a344bd4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.27-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.7"
    }
  ]
}