{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:87f1a5a0-6888-58c6-913d-6d5ae0b8aef4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.21-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b93339b8-631d-5ba1-a7ee-2088a5695922",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.8 of org.springframework:spring-websocket. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7d2bd38-769d-5f27-9819-dec0430e9c98",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05094c88-6a69-5990-ad8a-57e140b8b9c3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00cc0227-6ef6-583d-8c23-2f140e1c6747",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c24052-45bb-5350-a70f-bc331f7fb94a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dce10b6-8e1a-58fb-a52d-cc1bb58fee67",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64b19aa7-8900-5d44-bbf2-27c5ce1d273a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d704a3fd-065c-5ec0-b3fc-510293ff9334",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:517d0364-4f0d-53b6-8c04-e6f23cf0dd5c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb368bae-8bd3-58a9-9e7d-34344757b0d4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9342a27c-5649-5f31-83c2-54df91e6f952",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e2ce74f-6cd1-596b-b591-75511f22a927",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc1ff27-7acf-5ebe-acf3-650accf94a81",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:783bd4aa-e1bc-5269-831f-70d1af7ff8b2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562f85a7-e97e-5d9a-9810-bb536952c45e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11d64b7-0df8-5932-8bf5-760d8d5c8e50",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f1ea9d-54d8-567d-9fc3-dae968383005",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef4e8b4-dcb8-565e-b044-fa1906a9f6f0",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80f006b-f3bf-5e53-a0b2-62532c5ad333",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee05729e-2b16-5672-afec-1b04dfc4ae6b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6691f01e-0f89-5585-9125-0e42e9b1545f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4232795-7ef3-5061-91a7-0d1217ad7596",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2238e765-d149-584d-817d-c9254dd6a242",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c19f7af9-63da-520d-b0c3-b682acf6e47f",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f67de2bd-7f96-5660-8db7-976d5c62e5fd",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
    }
  ]
}