{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5bc6d56e-f0e1-5c1c-964b-4500b96aadd9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1",
      "version": "5.2.8.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39613cb4-8332-5a9e-ad8a-847e2bdd0cf8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0c77ea8-7978-5549-a87a-a9b9bfa29f26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5afd9b9a-a741-53b5-8080-2788dc08401e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70398eed-9c06-5050-bd96-1cb63bc04a17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6f83f24d-3932-5b0f-9847-ba26d681eeec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0b08817-ad96-5fe8-bfb0-cccb04bbe45a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:768380c0-2494-5c4f-8d90-dc28087504bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba672668-5d98-50e2-90bf-01409b0b0e40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ccfb229e-2273-59b6-9500-b8e02371c7f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:74900456-cf74-5819-bc88-77131532ab96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cff8586c-cc86-5ea1-ab35-52eb82389f93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:27a656db-06d4-5601-b8e3-a9c630440e2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6263a470-c9e3-5cdd-a57f-9accf896203d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66be3fc0-9973-5f62-940d-3a8243a0da18",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ac5b7d1-463d-57ef-8ffa-e2581417bb5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50900fce-7290-541f-b3d0-7214ceffac71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d069013f-474a-50a9-b4e0-94780931c6e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d356bc11-c2de-5a7f-ab14-45340cd1f340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b15fdadc-02f1-58e0-8b79-c3569b47ea26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db86da99-2dfb-5e4b-9492-a97281e2bd45",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.2.8.RELEASE is not affected by CVE-2024-38820. The vulnerability requires locale-dependent toLowerCase() usage in DataBinder's disallowedFields matching, a code pattern introduced by the CVE-2022-22968 fix in later versions (5.2.13+, 5.3.x+). Version 5.2.8.RELEASE (July 2020) predates that fix and uses case-sensitive direct matching without any toLowerCase() calls. The vulner...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:17611fec-8240-5e78-82af-112c67bbf358",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3a91338d-d4a7-518d-9cf6-d79b1a6d61da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa294e6d-d7aa-5b47-946d-7de6d20eef4c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket. not_affected \u2014 Version 5.2.8.RELEASE is not affected by CVE-2025-41234. The vulnerable code pattern (PRINTABLE BitSet without double-quote encoding) was introduced in version 6.0+ on Feb 1, 2023, approximately 2.5 years after 5.2.8.RELEASE was released (July 21, 2020). In 5.2.8, when using non-ASCII charsets, only the filename* parameter is output, and double-quotes are automatically percent-encoded because t...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eb8aa4db-7a51-50a8-a2e6-5af6eea1e3ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:25fd5b63-25ef-53a8-bdfa-7a0490c53dce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f8aef903-d3ec-53cd-90f4-9a3beac412d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5782d371-cbd8-5fa1-b55d-64de5ac56686",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81e8950d-f14f-5684-94d1-06b58d7feb13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9bda0c9b-24a3-58bd-990c-601494ad1e6b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:81923606-540f-5c63-a780-7cbd7081e2b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc403225-1230-53d7-9c2c-284d9bd6759b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6cb447c-f0af-57e6-a53b-9e31fcc9f26e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:70d119a0-7eb6-5378-9ce0-310d0a826e3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c70b66bd-ffd9-5492-8e1a-390b67e3b042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b0ab336-4d82-543e-a931-bdc296c0acb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ae8df69-f9f9-551d-8b44-ba8212c0c352",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:29f1430f-54b6-51df-89dd-a251ecfe9efd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf4f3d71-6816-5513-848e-0a74e75d6bc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3900dcbf-eefd-5841-af56-1e2ac38fb02b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dad382fc-e586-5a41-8bc9-e1050fdeee62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9237d59b-2d46-5605-abb9-1721df46d83f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2ff9bf10-35d9-57c1-9aa5-b8ee077386f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e0ecef09-93ba-56a7-b31f-5a9c319c65c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:181a0280-0761-5a54-b671-72bd784343cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:952c977e-d44b-5339-819e-f53149b5da0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e394fa75-942b-50f9-b760-5ac4f3610e62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:08df3af0-6391-5878-bce2-860dbf253bdb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:20ff1592-6218-5b7a-b2c3-0362e4b6d90b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:231082c2-ea41-533c-8c93-069400907dec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:909cc181-db2b-5b07-8448-bcbaafceb4b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94bcd1eb-8c57-523b-b632-ce19b24b704e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ea47631-901f-5f79-a1ed-ed78eb0ab83f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d013a943-b03f-5f00-8680-d331aea9f9ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e7c6e2a4-fca6-5212-b178-04bd4b79dc0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:14db8d25-5b0a-5c61-b9b2-4888fe4b2945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7ece56c7-09b5-575c-80db-aa968ef51c80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:862d6afc-21fa-5e53-a7ee-2421ae3a7a4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bba7e479-cc8e-51e8-af2e-1464fdeb11d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0d6c447-6e2e-5929-8e7a-d1a7dbe5f587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6946d336-d99b-5c64-a7ec-56e708639c06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e63f0634-05b0-5f97-bf45-4dbc24997271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.8.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.2.8.RELEASE-tuxcare.1"
    }
  ]
}