{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4985b034-aae6-5828-a7d2-ba4a3722a3ad",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.29-tuxcare.5",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:965bf686-cf55-586d-94cf-cf36c00e78dc",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07e7b5a6-9801-509e-bdde-3b6371bcda19",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aba7547-7a59-5080-b020-a2226124ffe3",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8319f1b-30ff-5285-9f15-ca1e39b8a56f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128f880b-2d01-5074-abae-b7521f7ffff5",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57e6d66f-13d6-5935-a96e-76d6bff81fc2",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eabb45e-a6e9-54c7-a4e8-7586d288e681",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0f1be7-bb1f-5561-9425-402fdeae37af",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba4f475-5857-5411-b545-f6e20c3ecedd",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dafbbdca-7d46-55c4-b505-f7c90d820aa2",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aaab719-59d4-5595-a615-29ea1d13efd1",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78558d9e-5cb4-503e-8ffa-2301dc35da59",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.29-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbd5d609-084d-563a-926e-a4b7aed40e9b",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235c34fe-c896-58e9-b0d5-a1d8823dea13",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e9065b9-e10c-5fb6-aed7-2444611e4ef9",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f787014-ec87-5366-9c2b-6a333910a8d4",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e2cd95-65c8-5d80-bcb5-e0299c5dccb4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ca0e1b-322a-5003-9485-0fe7186ce302",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:179369a8-846a-5234-a0ab-8a078ef08a57",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0de7198-2a48-58ec-a491-eeba55f7a480",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287efd51-2096-5f52-a35d-09127b9645bb",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0839e548-e84b-5c0a-bd2c-1c5b283a3f79",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b32da543-e461-58a2-af76-bf458461c447",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.5 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:154fa596-0d29-567e-b65f-9d21ba43d0b0",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f14192-b850-5db2-a421-60e28b9b6b41",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f37a865c-8957-5a7b-8ce3-e12fb795117a",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:604bc99d-525c-5805-a0e6-867e5caa466b",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dfb09e9-dc87-58bb-b542-14cd312577fe",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ad481d0-c0be-56f2-b28d-2cd6c68e0470",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0269a202-dff9-5a9b-9530-925dd0f669de",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcc139a5-304b-5030-8198-c4df9ec9461c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd4520e-3cd3-5e3b-89e7-62c93025f0db",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26cf258f-b7a0-5356-b442-9d27e91f741f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9782f22-ece7-50ec-9f54-9efcdeba5ac5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4a2c93-e29b-50b6-856a-a145c161e9ac",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a98a681-a90b-5220-b27a-0e77209d706e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e29a5143-bc54-5761-a667-faabd78cc51b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.29-tuxcare.5 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.5"
    }
  ]
}