{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:549911f4-f025-5f8d-892e-e95eb688e0a2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.21-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b459a2ce-70bd-506f-9099-9a7feec95ec0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.9 of org.springframework:spring-websocket. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:864c0725-5442-5a70-b0b9-4671f4457153",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:723d6bc1-0357-5568-8b5c-2527c5e78d1c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39cbfa10-bdb6-5e46-9d18-160a0b077c85",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e50eff-5a69-5269-b313-7612b2b47892",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c72789b-f922-5db1-a303-81b32a15b6fe",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6df29e-a5eb-58ed-9c29-b9a04ed87f0d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2435c03-07aa-542c-9c34-fcfc904aabb1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cca4e36-f3d5-5754-96dc-256a3d5f2338",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a805f6b-dfb3-5106-8805-d193a09d1c4b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:594cab81-19af-5a64-8291-2321112ab2b7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdba0da9-a552-52d3-b18d-1bc787aca1b9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c15837-608c-524b-8c80-b62c0127435b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70dc5549-2cde-56ee-8044-5e6f06ab762d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76730e22-3878-5f0e-9863-811adade7b5b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a711a9a5-4313-5708-8ebe-2faa881bfe7f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eda4289-2a76-5a0a-a3c1-4cbf9e2c282a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc23ec48-efd3-5def-9441-a67d0a0ce299",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bbdd34-5565-5133-86b8-4c79f7333639",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92d65b5e-0690-52cc-b63e-d2b84d716ba9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b259da64-1e3e-5735-9e19-5529bb14cb3c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74bd3d0-b198-5446-ad9c-6fd198980372",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b27df8d-db7b-531a-a570-7133f47c1a70",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1780e9c-3d36-577c-b7b7-62fad4f36d4b",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f3d406f-4734-5b48-ae81-759a879059b4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
    }
  ]
}