{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:453016b4-eb72-529a-b1ba-c393a1d033c9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.39-tuxcare.22",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dea20892-5065-5e63-8678-d01c550b62ef",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38aaa8be-7b81-5ca4-a372-4a9dccdddc19",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.22 of org.springframework:spring-websocket. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e6d067-6236-5ddd-93b5-15979ba0bec1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a665395c-be2d-5c14-b6a2-961abcc3a014",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84ce8302-63fd-5f4c-af64-9937258952f7",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db1fa3a2-fb44-5dd7-ba90-4b324067c6bd",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e42e11bf-bee2-5e4e-87f2-cb2d119710fe",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53e8b47-38f0-59f2-b1b0-0db30f118acd",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.39-tuxcare.22."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b002d3-efc4-53d4-a3bb-2ce90138ef76",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b240bf9e-46d6-54a2-9ba1-34f0d60a2572",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45af2476-57fc-516b-99f0-775422f8ea05",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8361611e-f68b-5135-b3bb-dd93588df5a4",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0170949-a13d-5121-9f87-a03a046cc26b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df95260c-5f7e-52ec-a7e8-2980d4d3a972",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:019c3be2-ed54-546a-b4c6-9222dbc86fbf",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd96dae3-1b30-5f7a-874f-7e1a736a5b28",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64677fba-7cfe-5d35-8755-edd1988e507b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d704db42-472f-58b6-b115-6394e54b8eec",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c0ece4f-29e5-5481-a718-d9449557f4b0",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41840 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ea577ee-87fc-5a8f-ac67-548bdbb6af0d",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79e4617c-3072-5bbe-bf31-adb516c0eb17",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37613720-e7ce-50d9-bf45-60ce7c7c7ffa",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36c046d2-9102-5f58-a8e8-b2dbcc78443f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c2482d-b9f9-5359-ac5f-8d0f4ed4def7",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a20cb14-e591-5704-a0c7-f8730e40320e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8edeedb8-4158-5bd2-b3f1-4594f99a4444",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64efe9f3-4be8-598b-a75f-05e6aa63493e",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dbfb167-5465-56a8-8054-13c356b21170",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945a1cc6-255d-5d1e-a69f-7e97fdc47942",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a99a598-5eb4-5ca0-906c-e2be4e1ab6fb",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0064ee87-b454-5e4b-8c66-3a40711af053",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fee219c0-2443-536b-9f50-0a13cefdb9c0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71f2bc7f-c847-5195-992d-5de7fb7e850e",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4b83e3-c3bf-5576-8a78-f043dc51f207",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a07e5e-bdaa-5924-8bce-e817787e412d",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c8e85bc-3842-57f0-a99c-21f482abff5b",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00e09e5d-0dd1-5aeb-ac7f-53615c05e8f0",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cdc3b2c-d988-5af0-b30e-eca5de3208aa",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f118b0-7dea-5bc0-b166-4f5a2f9e2a40",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aadc9af7-f519-5ee4-b31e-34bed267e824",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b9e16e4-4663-5683-b50e-e989f6dd6e0e",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc4e3df9-0cff-5e03-bbf7-a01794b00719",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ec2d89a-7878-5841-a260-dd8cc69e38b4",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03008f43-e8ce-51d8-9093-71c7fd5fef11",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9394d140-85c1-5f16-bf92-a992585d7d67",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:384ae1a6-2ae2-578d-ab45-727937708d80",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40159dd1-5555-559b-8027-48ebe2140708",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.39-tuxcare.22 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.22"
    }
  ]
}