{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a1798bd3-b07b-5833-96cd-adda7a2a2096",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.27-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f40b5194-d5b8-5c35-b52c-ad8a3dce91c7",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2317238-e471-57eb-83e7-bdc2b2c36132",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa410cd-210d-578e-9a17-2c01f3601596",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff997075-c909-5a9f-b1ec-92731065edf8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d47e759-ef74-5f76-b0b7-1da60e3bdd2c",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:105cd755-9b1a-5ff5-817f-d49c9b6c7964",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5740ef13-5d23-55eb-a6c3-532edb2d5ab1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7def4c0-8b8a-5d19-91a6-0aabe3dcf511",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90790cb0-9673-53a5-b62a-04b8967e915f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5215436d-c21b-5429-8dcd-73b9d13ede8c",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17b972be-81c0-5182-9be0-a21b8826582a",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f61d672-727a-5cc4-89b0-95c61003a150",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.27-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:770b28e5-9f9b-54b1-8513-b8b42ddd2a00",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a082121c-703e-5640-941c-7fb241f86964",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a80076e-3fbe-5211-9088-7fbc35582799",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac88431-6338-5776-a0a2-ee72e8f02937",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9f33e4-f012-51b2-a0ee-08922bec8037",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a3a79f8-b999-58fe-b01a-38ca70090062",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc426b62-fe97-580b-a25f-89d71ffb404f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6e0d12-4021-592e-8b81-cc10dec1b09c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b70762f-7e4a-5cb1-84dc-913df147d754",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed574a90-0b26-5f20-83a6-49514156985d",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c7623eb-79a2-55b4-9906-4911817fa0b7",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.9 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82dff073-a01d-5933-b960-7ab21591288e",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:629cae9c-48a6-5760-b0e5-14032b5c9f94",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a56feb5-da99-5e27-952c-fbbca9c53d43",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0280616-66b2-5e0f-ad45-97384d8bdef2",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ebeb0c-3d77-54dc-b3fd-4dee64072932",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:976eb9a6-b600-5b8e-b0bb-90b6e0bbd6a3",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16bb2d15-a8f4-53f9-9603-0af6bc420a9a",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.9 of org.springframework:spring-websocket. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b21b4d93-99d8-5d8b-b8cf-04c78266c838",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9778e33d-0729-5291-b252-59319a84c46b",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e83bcf2-aff7-5ca9-93f7-15e43658bf69",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3481f7f0-eb7f-518e-bc81-8cb3333ff7a2",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f28158-0610-5abf-99f6-c8da392d27d7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44e3a3a6-ec52-5cd3-92c5-7d11d4f87559",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f8d93a8-36a3-5f8d-8907-0d337b326715",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ae9f84-4d8e-59c1-836a-c63925c3ee18",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f40e7d7-72ba-59b6-940d-023e77dace92",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a09ef424-81a4-5404-8f92-29403d97641a",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bf1e4d0-8128-55fc-96d2-abe93d9a5c39",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2236a5f-0e5c-583b-9fac-d75baebe2ee6",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35a56cd7-1fc0-56b4-bcaf-d23fbe4c4e90",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b65e666-8e15-568e-a522-eef931ef2627",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ab536a0-66b0-5b85-9a22-9dd19a9b4acf",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f0fc8a-d1bb-5440-b99d-746877c066d7",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7436b46d-8902-5581-8626-6acb8d578d04",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ab221b-ed46-5942-a76b-ec2ddf4694be",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49d50119-c421-5f36-9e65-a61fb72dc8d0",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fcb6d08-b4ca-5a3f-8df8-5925b02e758d",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08f40c2f-fd31-5232-8f60-49271088ed2a",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.9"
    }
  ]
}