{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5e7ea034-fc06-57e5-9374-cec426459946",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.20-tuxcare.10",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:03a76fff-dcde-5bdb-ac7e-ef7e63c5fcc2",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.10 of org.springframework:spring-websocket. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc45e4e4-8988-5c33-831b-a1b817881648",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5c7d780-2d3a-5d14-a8d8-6f1f2db09e76",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d235e8ab-ff73-5781-b02d-424a7d98e8c0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02173ad4-735b-5a73-a41d-917fc4a22e34",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b185d7-7dd1-5b7e-a287-a1f244d8d76d",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c37a9d3-a639-5b5d-a535-7ea94396b18c",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b745b715-d5de-5a39-b04f-99d5ed425920",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4f51ea-9a1b-5742-ab5e-ffd7f6219efe",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a1fc3a-27e5-56fd-a9f5-d3ad91d4fb3c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b06dfd-c3c2-5f58-a6d5-85f93243cd85",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00588a88-3706-5f3e-9f3c-f4ea5dbf02de",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af229698-e5d4-595d-a603-5891b89e0f4a",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1e6dd0-03e2-5e8e-b883-780d1880708b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a86c2c2-d247-5886-b488-29a2665c82d0",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7b4bcb9-8ebe-5486-bbc4-fdda6f9d33a6",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0093b9ac-2f5c-551f-81c4-eedcca3f666e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c484c78-0665-56c0-98c2-fddd4afe10fb",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d4822e-8ac6-54df-b17b-d4c51c934906",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5bff5c-5f3e-52dc-a748-9ff9922ee01a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52764899-61c6-5e0d-ab3d-3c4ff6a903ee",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c0c400-548a-5233-821a-1b73746ff779",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8153d8-09e2-53a3-b70f-1c6153e79322",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3747160c-3f1e-5a6e-9940-d3e8fdb6b95b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12fd5be0-0386-5f9c-8625-7415e3182511",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e3047a-5558-589e-8793-9e73eeb21799",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef84bbd-378a-55f0-b6c5-1433428c53ec",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46bd9f88-5ce7-53ee-be3c-9542338cbc23",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b2fc5a3-fb28-5692-8bee-b188a084fa52",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:836c4a1e-833a-5341-9abe-3f634aa078f8",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205e4629-1004-50d0-b42f-48cef03d8b63",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4743ba7e-b4d0-5da7-889e-e45a8161829d",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11f6e9fc-2054-509d-b9e2-b1f82d7a3433",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2545159b-9f1a-5f97-bb57-5450bf54ba8a",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0963267e-f94d-5b7b-a15c-1c5b53b85036",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bb06a5d-efb0-51c5-8549-99fde5c5f283",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3afffc77-b850-5921-88b9-d1a8796e1283",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47eeb7d9-3c82-53ad-8a32-99cc93941520",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca64e43-9fb4-55e6-8dd8-c7360ac48d39",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caf83f63-b62d-5e10-9418-86aade000281",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.1.20-tuxcare.10 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.10"
    }
  ]
}