{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d42800ca-e850-535f-ac1d-feca9ca3e0ca",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15",
      "version": "5.3.31-tuxcare.15",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:3917eb93-cf92-5630-9d27-d0c11d2137e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.15 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c3dada42-d0b7-50dd-bdd4-e41cc277844b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c32645cf-2d1d-5c46-a2ea-1793ce2585de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:7a790361-0c33-567d-b81f-7c1e5b6495e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:f53e06b1-e39e-5eb3-bee9-3ec66622be15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:73168793-ced8-57a3-83ac-07ec64099dee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c2dc475f-f643-5f93-b14c-bf68df4c8bf2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ef7181f7-6ceb-555e-8b11-0eabfdf668ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:80bf9f3d-c864-5ac9-aefb-722b3e23b7a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:b85d7cf7-e9ed-5920-a626-410db28e30fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:75446c7d-d965-5cf6-bec8-682cdd1db1f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:14d8d1f3-bbb0-588f-9fff-87086f5e2bd0",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.31-tuxcare.15."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c234923c-95e3-5cc2-b9d3-c8864f6db94e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:f40c3265-051a-5cf5-b6cc-b45ac379b845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:34e4ec01-aab7-5f45-bdd7-221178cea4eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:81ecbbd1-75c2-5675-86af-4bd532316812",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:fffdf510-5f6e-56b6-a067-f54c47e06c3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:2fd0402f-0003-5f0c-afee-0239214f3bc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:8c1922ea-1f49-5235-a50c-d8dce8882b8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ca19d932-f7d9-5916-984a-6dc33a0ff768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ad73ac81-f608-5c5d-9484-3b22cca4ac75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c0f93c87-62a0-5cca-a1d3-d2e31f8a00fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:664d1cf6-9bf1-594b-bc8a-b8327eaeb4ca",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.15 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:6cb66403-a3f9-5a9b-bc61-76328d8b0d5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:994b75df-fbb8-589b-8e6f-2a7403250414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ef63d080-6707-5635-a390-510ed2941507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e5571cd6-6c71-5ffb-b1c4-098605d4b12e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e80a6e81-7dfd-5ce3-be7b-012d3dd19394",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:51526aea-77bd-5c9d-ac4b-893af224262f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:a8b77826-b5b9-552b-9e84-b08be3224b52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c74f3b51-fe30-5efd-b266-fcde6004e49b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:749d70cf-ab43-5e97-bd00-96a6921d8ae4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:7a51a4f7-0ebf-5bd0-b089-b08901742308",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e5b65562-28b4-51e4-8fe5-c07869a916f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:6f8afb4e-7d8e-5a3a-a6d9-7b7d22e672ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:15557738-afde-5199-b068-687cbf685429",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:b229d795-1c1a-5f65-adc3-7ccccde79cd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:9142c1f5-08a1-55a4-9d51-f04137fcca8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:811e8526-3a5d-51fd-ac04-d467251dffa0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:0be8f860-6e38-50a0-a9aa-f05bdd32f616",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:1534cb20-1ce5-50d2-b1d7-7c81056bf56a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:65ece20f-b52d-5c82-a306-8b52aab09d6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e2291a3b-f2c6-5093-83b5-99ef52426141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:98f9cf31-3c16-5090-8fd4-4cf0d3062fd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:36957628-0790-5c54-94aa-f9e86215faef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:64828758-5d80-5710-b9be-4ec849808e6c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:2faa1b65-f1a3-5de8-b849-e79d047c7ff0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:de66d550-b623-5951-9be9-ee383a0549fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:b8420a0b-99b8-59c9-b9d1-1116a927aa22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59313",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:3a1dd6e0-7dce-5f3c-b64a-9de8776a9d73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59313 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:fe194db9-5c02-56fc-a3a5-83258d04461c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.3.31-tuxcare.15 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.15"
    }
  ]
}