{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:188994b0-8529-57c3-80ea-a9ceded1d02a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.0.12-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0580c092-f6e4-5e9d-a378-e5f609dac035",
      "id": "CVE-2023-34053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34053 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56920c12-1f46-5c54-a5d2-f6da13b2a912",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b94c63c-1577-53e7-9fc1-7b37ae9d649e",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19919078-dd8f-5a35-a292-a0773226b65a",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0b8d219-6a0e-565c-96f6-7b6e7b7aae5d",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89b4c8cc-a504-5b09-9efe-d68bee048cd5",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00adbbe9-de5d-54ac-b857-2ba24a99bd0c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9795280-f29a-5061-adeb-d575c353b382",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fa6615a-cd60-5391-b18b-3e1ab15ecda9",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3f2d0ca-7030-5c90-a0ca-3505872885ca",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f70448f-cef0-5e98-bbaf-cb49fd4ab148",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c955b55-6d88-5ca5-816e-719023769e6a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adbfd722-7885-54f3-a315-4b81db767c89",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f08f672-963c-5f0c-bc9e-d007a5c75df7",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb90fc1e-5b84-509f-9b2e-a202047bed2c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f99cbdc3-c443-5694-a373-cacb220279b9",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb0740b-2b28-5878-81a5-78b441ca30db",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd214e2-fa25-5849-a6a6-93b8b1575bc9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c389003-2ac1-5f81-9a9c-00c74c0bb9f7",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:891046cb-b35e-5f1b-a2ce-c5df4fe8ddb5",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41839 does not affect version 6.0.12-tuxcare.1 of org.springframework:spring-websocket. Current version of spring-framework is not affected by CVE-2026-41839 according to the vendor - https://spring.io/security/cve-2026-41839"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6fedf06-b396-5f3e-aafc-76b122e25bf7",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:397c6d2e-2089-537a-85d9-fa2ce2cb69b7",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dbdf854-7f87-5e0c-8fc3-4bfb8563d936",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad9f1c2-cb06-549e-b238-aaf46cdc1251",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69d3891d-f8f3-5802-ab9b-bcbf324889b9",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae7495f-b6e8-564b-aa9a-9ff2afbd5ae9",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36ded881-f218-5289-bcc5-7b54f8b3187b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a61f516-74c8-5bc0-b3b9-efe4069c1313",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adc19162-20e4-546e-a9ea-7365649a7d6b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5403fcba-5195-571c-b0f3-3293a1fb6c80",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f5ce44b-5007-5ba2-bf55-8ed1d8eda1ca",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7572415-2c68-54d3-bb2a-42d71a1e8b52",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dcf65a6-480e-5f84-8ad2-dc15c37a4f9d",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a72b2886-5579-592d-8628-e8d4c7401245",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b71106a-1604-5d67-ba8a-e1216658686d",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257c9584-2a08-5a18-b270-1c3aacea1066",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8350b45e-e825-5878-8f78-0146f2079c3e",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74ec61e-7e17-5c6b-a42f-7a59c5c5623b",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c51ff22-5dee-5f4f-b9a0-22571b51be54",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f2daa0-cda4-5c82-8509-a64c6be8b6e5",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad0ba3a3-acb3-5789-aaa4-10bd3e6231e9",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:856cd27a-3b46-5fde-b135-7af8d5a6fa84",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaf47baf-a8d3-5b7a-bfe1-d69a5008988e",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb12e9ee-d2fe-527e-915f-e42b6cbcf89f",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6fc29cf-aaa2-56d6-b30d-2f710b0ea64f",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a2ad84-9115-58c3-97f1-2baaec717aba",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f1f092-c3ac-5fd2-97bc-eb7da36091f9",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.0.12-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.0.12-tuxcare.1"
    }
  ]
}