{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1c804801-4ddb-53cd-9293-517d5af6fe02",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.37-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9e86c8f1-cf7c-5c5b-a5ee-32ab3091b386",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bd79211-5367-5b55-b577-8cfcd5a288c7",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ac07850-73a3-5541-87d9-edc0bc7441af",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fbe6218-3a30-57b1-be23-4220da434bbd",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f48b0c3-68ac-54fa-89e1-6b29c3f0a0f3",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdfbcc2-b435-512b-a9d4-03e5949796e4",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a059bab-d5b3-5cb3-9f0d-533d13f0c2fd",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb381fdc-08c7-5f01-b809-1c054b6a57d7",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53ba4ef7-74f7-5fa5-bb8a-6f66e955bd7a",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599674ff-990e-5707-8837-d7fe772ea0c8",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d53cb8-b1a7-5bb7-9b78-2c64d9ac570a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8f4b84a-ebf2-51c4-a97a-9ea5478cf036",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f98e5e5-122b-5d64-97cb-db0cc75a7e48",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac14ffac-a34c-54f8-a742-cf942b38de94",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24578a92-9820-5e1d-ba47-602d6cfc44d2",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6191a39b-102b-5d09-b4a1-91b192e82437",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e83167ad-bd6d-55d0-9be9-9fe5c3c566d6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afd9d0ae-796b-523f-9bfb-8cc3d4053011",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9b07c89-3933-5e60-abfa-1e6cb6f73343",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a10c26-5a00-5e66-a0a0-aa451656251a",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b28478b-1146-5041-bf79-db0109a1937e",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26a44905-d903-5e46-b3d8-fee95a5d7d5c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:289f8ffa-0dc4-5259-8134-395e754abd8f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd238cd-a651-504a-b473-86fb0c266fcd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2581a772-70e0-5ddf-ab93-eb453fac5b2b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a978382-46ce-5b51-b6ae-6a0c1e24cd35",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dde7801-8c83-5d0b-862a-340a19b2c743",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f0f1f5e-8d67-50b5-9a13-bb911d35241b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-websocket. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:340645e3-2a4e-5d20-9522-d89917f74056",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e6f8430-eb90-5928-8fba-67f2ba13c0f0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8765dc59-00a4-50a1-8dff-a24dd02b3c48",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:112577a2-9b79-570a-9652-29c587589e28",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a6fa6bb-707e-5653-9cf6-f78b871c86ee",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41854 does not affect version 5.3.37-tuxcare.9 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.3.37 is NOT affected by CVE-2026-41854. The vulnerability exists in RfcUriParser (introduced in versions 6.2.x and 7.0.x) which incorrectly accepts malformed IPv6 URIs like `https://[::1]resource`. Version 5.3.37 uses regex-based parsing that correctly identifies the host component, preventing the SSRF outcome even when accepting the malformed format. The architectural differ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:995dc439-50ed-5c81-86b1-67cba3abbfa6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.37-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.9"
    }
  ]
}