{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7b75eda1-f076-5816-9126-70c4bf346dee",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1",
      "version": "5.2.10.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5cfb099-df8f-5a4c-bb5d-7bf1915b96a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a68389fd-9671-5565-95a9-b6b93620ebe5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85c83156-9f02-58b3-aefb-a9a2a9214d62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8be65724-475c-5a68-9106-3c573cae0985",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26ee80fc-6c51-55c2-bdf2-4f03bd0712b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a7f6b5b-38e3-5d75-b217-7cb81a8475f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:599ec606-1ec3-5fc3-b066-22c6efcb897b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ca99395b-0e30-53b3-bbd5-0e6123ef38e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ba01439-ca4b-571b-87e0-7946b676a526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7780f0b7-34fa-5810-baff-95d15c1a4c83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d5704878-ee39-5e42-a973-6290ff05248c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55e82c4b-6498-5ac3-9328-ee6148262157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e9544a3-8509-5f87-ad8c-ff2605681a9f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f0f6d17-2916-5e9f-a3a1-64607611c077",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02996917-db6a-563a-8a41-9d01db5f0e23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ca57474-ae93-57bb-a740-28815370c02b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c8945d68-579e-512d-9459-b74754609ad5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:894f05ea-bf78-5cdb-bcf2-c68700ce6380",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f3ae3cc-fb6e-5b85-9ada-b3aad6b8d613",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket. not_affected \u2014 Version 5.2.10.RELEASE does not contain the vulnerable code pattern described in CVE-2024-38820. This CVE specifically affects the fix for CVE-2022-22968, which introduced case-insensitive field matching using String.toLowerCase() without a Locale parameter. The target version uses case-sensitive matching and does not call toLowerCase() in its DataBinder field validation logic. Therefore, the l...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b653e281-4304-5b7a-a483-016ddfc3a776",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2297165a-81fe-5beb-8387-88813f05f7a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f23b5ed3-fd09-55a2-b2e8-6421a94a93dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0562d18e-4ebd-5be9-b4d4-c7cb727c4f7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:05e2a02b-137b-59e6-bc3c-4efc0333b08a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:036edf45-5202-5a5e-8674-1463e1897b14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ad3c4f4-cab4-5620-ab30-aaeb9c0ca67e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3921db47-d911-5cd1-b304-76b18c1095ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bc270025-f2c1-5a41-b372-29c6977897d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1754c515-48ce-5a06-a0f4-d91f590ee033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e6c1cf5-dce1-5bac-a6bd-a76228cc660c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6376c2e-3bdf-5f85-9d2f-f7363c4afbe9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket. not_affected \u2014 Version 5.2.10.RELEASE is not affected by CVE-2026-41840. The vulnerability targets the PartGenerator/MultipartParser multipart parsing implementation introduced in Spring Framework 5.3.0. Version 5.2.10 (released October 2020, before 5.3.0) uses a completely different Synchronoss-based multipart parsing architecture that does not have the vulnerable BodyToken buffering mechanism. The vulnerabl...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9b7d5820-2511-5036-bdf5-d2ef02ef971a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eca8cda1-c2a9-57fb-a216-d9179eaafee6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:17d7352f-4e83-5a2f-a491-7c809a85ea8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:831caab8-6144-5474-80dd-f66d1c509f85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4cd212ff-06b3-5956-b2d4-57ef51cb5886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:25518b0c-9ba1-5fc0-85f7-6ebab819ec89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b3bf07a-f5fc-5b57-a369-3d2d6a26ffcd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5cc15ea6-cbba-5d06-bcea-23cfb358b2e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:09eaae4a-59d2-5336-acd0-597f5311a210",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81dbae19-e12b-5b97-b58a-bb6b0cebdfe1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:919008b5-cde4-5178-8868-30d03b64eefd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa7d54e2-3ad2-5bc5-ae05-1a283e65bd65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba6b7614-39db-5e98-9c4e-073fe98e55f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37da557f-3136-5f6b-901b-da68cad3a502",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50560a8a-1143-5ab8-a777-999906c2c78c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:871c0617-97e4-5de6-946c-ebbeb89ad2d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79973419-0ad3-53a3-a451-003c0d5e5336",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dfe96abf-a659-5462-9d04-290fb0ce87d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a44fa9cf-5ae4-5257-bb2f-e98ad18c883d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c60276c8-c4c9-5f8b-a217-46dcb8e69bcc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bb18a21b-d9c9-5062-998f-0a5cb4dd1f42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:31eda8dd-0589-51b4-b98e-5a4f10dabfc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d62992be-171e-5549-93c6-2392d1e4a6ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2bbf69dc-1f68-534d-b403-67f2b33226c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82823fac-afbb-5274-b64f-70de0effdf5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:87dad1d8-4adf-563f-88ac-5c4c94b44b03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e974d8e-7086-57da-99d7-c53efca161d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.2.10.RELEASE-tuxcare.1"
    }
  ]
}