{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0ea943ac-6d4a-5173-9727-f1e8f5fd1cc9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.31-tuxcare.6",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:47634a54-8b4b-51d0-9633-60a104445989",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907132c9-f1cb-54f1-bebc-ebaed46b9397",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b9746a1-687f-5c37-bd95-dc51e4e996f7",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b192b57-ccd2-51bb-9bb5-2b0c2a9692c9",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b144e8-8be7-547a-bd6d-aa3aa768e133",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad99eb19-1f6e-5a06-b071-247051324f94",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99da4143-d9c2-51f1-b536-dddffda51635",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da360f27-fa70-5bd2-be45-4230a5c37caf",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff1da945-cb5b-5a6c-a849-432302228cb8",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f545c26-10c3-5a48-bb91-7b0d7317fb2d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56234803-13d8-5324-ab8b-d7ad83226c6d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc556010-d497-5ad0-852e-44c4fb46f139",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.31-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c743b8a4-8abb-5273-a950-9a21b52a8795",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82092b0c-a657-5d4d-bfdb-0524d9e84a23",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98c32cf9-53eb-512b-aeb0-0e72655708e6",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efbdbfb5-6b65-53b0-9f59-dcbead773e5d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90607697-d2b6-5c08-95c3-c7c838cfa555",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df2908b1-f792-5f37-b868-fa9e3aa615be",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed70f8ed-40fa-5fd7-ba63-d7fe781673bf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9daa6fd-4ac2-584d-9b93-3dd12e77c500",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:819efced-1f0b-50e8-bcf0-e9fe7b00a77d",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d7c6934-6e89-5ac3-881e-52d0f5b8fb53",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d1ecc8-06d2-5aa0-8441-f94b46a2b3d5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.6 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35e0bb4f-ae93-5ffa-a165-45342184dd60",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d92c274-5e81-5479-a6f5-4b6042e7778a",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:670a1a50-c3a3-5392-b6ba-62f87184a9d2",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a0d5d9-d34a-5d53-9082-09c91418555c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d289cd7-9134-540b-b2e6-b630ddfb90cd",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c4037d-8eb3-5eec-b1e1-468333e503fd",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce2ca958-30f6-5837-9fa8-b186e7c2e5e2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:783b45a2-55d5-540c-a136-0a51a2bced49",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f74540e-4e1d-5369-901e-faeb7be7d696",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74dc278-c79c-5620-94d9-6ad3baae5d31",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8d7fdec-f248-5b17-b65e-c421ff43cfd5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b53e9d4-6cf1-51d5-8c7a-d1f5f6562554",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb2ed5b-7592-5c89-ba43-b4b0e2cf3cd9",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8774292-3254-5e85-af9b-61bf4053175e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.31-tuxcare.6 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.6"
    }
  ]
}