{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:195cf898-d8c4-55b5-bffc-8c8ac48f4122",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.31-tuxcare.14",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7404382e-268e-5d04-8eff-417b0558b3d5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ba2e0c-dc49-5bc5-b349-888ee9c26004",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcf1f56-2467-5e34-a786-71b933b34d17",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:076f5c85-de1d-5ce1-9893-5e41b50e504e",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb1751a8-47b4-5539-bc54-a6dfe948fba3",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915211a8-bc34-5d0f-98e7-d7c2ecd1224b",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:816530dc-d0e0-5bc6-875e-53ba7dfa2066",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d67ab84-359c-54d2-af00-79977abe2e72",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc9fee7-63cd-55cf-a916-6a2d51031623",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfcf6137-cb33-5578-93a9-47ef6ab7c2b8",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:829dfe2a-f2ba-5108-8f45-04f497ff0c2c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feeec0ee-baf9-564d-ad03-47f9d75b6623",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.31-tuxcare.14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b718cff-dde4-5b55-9ef4-d45a8ac39fca",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23f38154-f0c7-5528-81c8-f669bf033e93",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5701a854-ed81-5eb2-bcaa-5a6dd1810cc1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b367610-d195-53dd-8d0c-65983130b521",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b86a7b-411a-59b0-872f-bcb9844807ed",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4c3cfb-2518-5ef8-b7e2-6649e50ff818",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0661103e-7b52-5604-9265-463d8e5c4817",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2766184c-ad90-5e8b-8d00-7021ac761db4",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c5106d-9170-5ecd-9d48-b7afc15c841f",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92c5946e-37da-53da-85b3-15412a4ab02b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f929a65-4f7d-547f-962b-a4b0ed16a0ea",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.14 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:621bb94f-2522-58cb-a2e1-0c078bf49f81",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe8cd347-e223-5fdb-afc4-7892dd6ecc3d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b176146-3f75-5f16-bb30-87a07be93e48",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40cc117c-013a-5aea-aca5-f07539ba9a3c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60d68239-d46d-529e-b974-da6e840fb187",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c0c58f9-09d0-5273-866e-abf59eb72967",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2119a562-dfd9-54cf-94e7-1e4a9577dae4",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d30925-ae6f-500b-9a18-b715e1b8be4b",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0693d74-9d65-53ae-9e70-50607c386c1f",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edabe941-09dc-5113-b6fa-78d7f3495e06",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:385b7fd3-40c8-5907-88ba-12297d445f42",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49318c29-d915-59a5-8de1-681011f53916",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a98628b1-d9bf-5cbf-b670-b89a789dac27",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e89723-7906-5642-ae75-5ef9f804f70a",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a8f16c5-8435-5cdf-a39f-36875202e5f6",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:168977e6-4528-5bca-8d59-f0c0079a64b2",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98590d36-817f-55f6-b101-f321cf1926f0",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a391e54-1114-5f41-9e98-0b87b2d4b3a9",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edf7be95-c40f-54a5-a83c-7e92932ccd2c",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f5ab50-8241-5534-b68c-e8e585030e1b",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74685617-4e97-5e08-b3b4-b17896d6f24e",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8c508e3-7e9d-5a5a-b647-99e6b5b99cd3",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15bb2748-c314-5096-b354-328fe7acc5b5",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8298863-4b9f-58cc-a459-3cc377bc72cd",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75c9073-fcf5-55f5-918a-a67688d13dd3",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db262fa7-1183-5754-98b4-66d27a105289",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:926f1874-4e03-5f74-a594-7af77c995cd9",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:970f387f-c1f5-53c2-8d89-ce30791f45a4",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.31-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.14"
    }
  ]
}