{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ffcc6ddf-00cb-563b-bf51-9b5b03b2c23c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.30-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:321cd38b-3581-59dc-944b-a1e1c06ee0c9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c4a68d-2486-509f-999f-5ab73db5d2f9",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0addf12-e13e-5669-b0ee-48b49344184c",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8095a7d6-936e-59ff-bc34-a8ffbd373a46",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9245e4f4-9b03-57d5-8f99-287e133620fc",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13606638-10e1-5581-848e-f7887cb20d78",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d3546b1-fb95-5594-8670-c6963db72b55",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:607b7405-9454-5f13-8c60-1f73a3e32f1c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ff16b4-7659-5725-bfdb-92cff6c6dc1c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f076694-9f9d-5e3c-b8c8-afabab7ad6be",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:248cfb28-3604-5c9b-821e-f5f61626b481",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb074ca0-aee6-56f5-8105-216c7277f44f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40f3edd6-f261-5c40-b99d-ad5c2810669a",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0194c2db-7e5d-5d4b-a8b4-04639871ee5d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f18c1ce-f52a-59f5-a682-48ce9919dd1a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc2fc220-0ab5-5a5b-9142-f87716f732cd",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b40ab96-7941-5700-9d48-f28c5cd34e44",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028daf0a-437c-54e2-956c-aaaa6556caf5",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52c08d61-100f-583f-aa21-b702b22fd3df",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:214911b3-b257-5a2c-ba4b-c79ac6dc27cd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ba96d57-1d0c-5c00-9e71-b6617e40b110",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee097d9c-72b9-53df-86ec-dc3d5ada4193",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.30-tuxcare.1 of org.springframework:spring-websocket. already_fixed \u2014 The target repository Spring Framework 5.3.30-tuxcare.3 already contains both fixes for CVE-2026-41840. The identical patches were previously backported by TuxCare as part of CVE-2026-22740 (commits 1a619adbfb and ee9443b0bc, merged May 2026). Both doOnDiscard handlers are present in the current code: PartGenerator.java releases data buffers on discard, and MultipartHttpMessageReader.java delet..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:721777c2-05da-5359-b649-fb3483f65328",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c9f4ed0-99f5-59f6-8018-0d04314abf45",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddbd8aa9-5ebd-5a33-8f0c-be8ca590e454",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6831ffa4-8941-50c9-8606-5ef90435be1e",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8df32587-9f69-5eeb-8eda-03c146597c03",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65583d94-dcbb-51fa-a25f-9fff27372997",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e17d453-fe81-5c75-b047-f2f8643d8d95",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63218ee7-4ba5-532b-81b6-40939bd9bfe7",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da8c731a-1bf0-5fcd-8418-ae3f3536e80f",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd25528c-cbd1-5dd6-b352-bd5661e106a2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9e40427-3fba-56b8-a574-c0e33040bad5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d94729-9037-5d8d-99cb-0c3c587520a5",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7db4911-95bc-5f58-b6aa-550d69cb589b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87b06402-faf6-5564-b16c-e92b88afd2f9",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.30-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.30-tuxcare.1"
    }
  ]
}