{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8bdd634d-2f7c-5f54-be78-2c566f0d1312",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.24-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:999cdaff-1a7d-528d-a65c-0389a4512238",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b0bdf37-56c7-5d07-83f4-75d806fd0e1a",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63630b27-d860-53f1-88e6-91325f0c4dd3",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1def5af-0c1e-57d1-889b-516a678f3f52",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0f9865-0baf-57cd-a3f5-787e871238fd",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7540af9a-807f-5a36-87e7-0256ad653bf9",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95f39b22-913b-502b-8386-bb9d41c3679f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:631ef2a1-37b3-5139-a9a1-c05d061dd5f2",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4ff497-d524-5d48-be7b-80362ff6b1b1",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53807466-8891-5eaa-b737-3ab85a8eded3",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee8f19a-7023-5aee-821b-127652e592b6",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df67201d-1a7a-5eef-be85-879155fe5a60",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3c49263-6c14-5d53-9f06-8727e6452091",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94293991-fd1f-5809-ab4d-66ab979dad13",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44ef9b10-635d-52fc-87df-e08b0eb95ca2",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfa6574f-dc06-56e8-8e99-e99c1eaccb08",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2c871df-294c-5bc9-af0a-75622d553278",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73e99eac-d004-56d9-a748-848637556b7f",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:626ecac3-1c85-56d1-8ae0-28fa22c36c3d",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42385974-3028-5d46-a621-8e9d7d16edb7",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd49b29-70bc-506e-ae2c-c39800800941",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa6c13b-0717-585b-9274-71c511729158",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdc6ab1b-9dd5-5c66-af8e-bfd7ff78dfa4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75810daf-a671-519b-b540-e4352c330c06",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c21ef2fa-1b38-518d-9303-db274292e4c5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.4 of org.springframework:spring-websocket. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a77ad607-ab35-5422-995b-4ad61575cc10",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d28013-fb52-5d55-bb76-bdbf96120807",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c318a15-bfb3-5708-8c3c-6e2b5fb32217",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b75d3605-e0da-5b9a-8257-4f946e91972c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435fcc3c-0114-52e5-9f68-d9d2f1f0560d",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:263a1498-94d6-525b-abf2-f6c54ea061cc",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794a457f-9af9-5b79-a9ab-2955112295f2",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdb69303-1265-58c9-841d-f04f998d9e94",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb0ef72-052f-527f-b1a0-03c93743be14",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37eced34-a417-51bd-a452-4f8c80308c00",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c89a6d5c-f757-533c-956e-e7e30ed6c156",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd59caaa-09fd-5a2b-94c0-19ae2bbe4a5d",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e1e443-df92-5310-b61b-cca9e6fbc8ec",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862c2302-a85f-5913-961f-50fdc725fb0b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.24-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.24-tuxcare.4"
    }
  ]
}