{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a86871d7-f3f3-539b-91f1-24c5ba4199ff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.39-tuxcare.19",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:04a771e7-b440-5859-9410-7fc54272516f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08eb3301-2918-5063-9491-da764cde3054",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.19 of org.springframework:spring-websocket. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c744dae-3ebf-5590-8469-85ce9ae55691",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa1ace3a-6a08-54bd-aa70-8e998fb22adc",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0b7ae37-7eeb-5959-95c9-1745bc4e3ff0",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8a1ecf-67a2-5d8a-ad9a-7413dabd3784",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5365dc-47fb-592b-b1b4-7128ceee6eb2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e2f7051-1c22-5fe3-a57c-2ccee5ef7599",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.39-tuxcare.19."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d8dfe6d-9c4d-54eb-a48f-93c96d6e4f6d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ffb77a6-f01f-5f3a-a62e-85bad7da2478",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f59ffc7-650c-5cf0-be4f-87be60b7c4aa",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92f45438-303a-5dbb-ab30-319f6ea782ba",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce57b9ba-2f96-53f7-81dd-b5768c9ebaea",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411c3daf-ab07-5026-8791-30472ab7ff44",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b55719-ab5d-56c5-8c05-3de204f3fc17",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a48d19b-aae9-5ab3-8906-f7939a0e4e4f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d89ddb0-5c14-5f33-9129-0a6edf8675cd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd13d5a8-5428-5348-b34d-2a6f3a02e95e",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4652cb86-bc94-5b70-8453-b32b54c1c966",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05c3c3d0-3461-5880-bc05-1cca96879c98",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9eec02f-f652-5f36-aab0-f59636815408",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b823120-9782-5995-88de-cbdb6f951bcf",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91809d8-8ec2-58b1-bec7-76fc6010eeba",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5b27168-e682-55c3-bfdd-5988e3816964",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6837d80c-b6a5-5104-80c4-77eca1845b1a",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1921ecc2-ee94-5d04-9470-6757c9ed78e4",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ce8ee5-e911-5214-bb56-bb4397b2acbd",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25aae3ff-0e10-5746-a6cb-46f1006c244d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2525876d-cb53-53f0-bca4-fc1336fd932d",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b044c6b7-7465-5741-bed6-4a4b8e7326da",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:980f7a2a-0a6d-56bc-9d3f-e2b1210a679b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d3a418-2dc1-5c08-b38d-a80a5d260a72",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:152881e5-5f17-5ce7-be61-827a80bbbbfd",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a398b5d-d7c0-5c77-91fe-9eda78fcd71f",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.19 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.19"
    }
  ]
}