{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bda548d7-b7f8-58c8-a2c9-cc95002fd5e2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.37-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:31bb29e1-92d5-5784-8bc8-48d8f5061aa3",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac31cfb-7605-50ba-8d67-98710f4a08c2",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba403a27-f406-52eb-b7f9-c8ceaddc867c",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913fe68f-d0ae-5536-91c9-f6d0334a8b2a",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44c0d55-4b0e-54ef-bd6b-ec0a749e7a1f",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4bee71-abc5-54bf-acd3-668b804d3ab6",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a282854-b133-52f9-9bfe-45367706811b",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e3bf60-1b79-51bf-905e-6ff515614a00",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b371f99f-5823-5505-8b59-6fe68190cf62",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e013d835-a34b-5acb-96e5-656cf9915657",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635503a2-9ad6-5f50-aad4-9f76950038c6",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ed08421-ffe1-55f3-b849-853124bdaf87",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de26f6c-5fac-514c-976a-6465bf3e2105",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f19349c-09ac-5864-862a-80d7a705468f",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b3b9be1-59a1-5d65-ab0a-239cda0b34da",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd7f59d-0ac1-5290-a216-882ad4ddcda9",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf261f3b-d04c-52cd-9f1d-af680acb2c1e",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51175f9f-e34b-58d2-9631-90ae4fff9069",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fe6e1b5-d2b2-53a4-ae0b-8015f0068ed3",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.37-tuxcare.4 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.37-tuxcare.6) already contains both fixes for CVE-2026-41840. The fixes were backported on June 8, 2026 via commit 648b33d0a3 as part of CVE-2026-22740 remediation, which addresses the same multipart memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ec6d97c-a857-5fee-84f7-2ac276d616de",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3be198-2433-5bb3-97a2-2a1bd2cfbd8f",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5650785-aa9d-50ac-86bb-9bb390b3e6c7",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84788d06-6ffc-5a17-8512-0d559973f2b4",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cef39934-378f-5cfc-8664-3789f7eeec79",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ed6ec5-6b1a-5c98-9eb3-c9254530e6bb",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:360ef65f-eb77-5642-9b24-54785314151c",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ec247d-db29-5ab7-a6d0-de16b74c75e9",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b2325a2-47a7-52f0-b464-720133cd5c1d",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41849 does not affect version 5.3.37-tuxcare.4 of org.springframework:spring-websocket. Already patched: all patch commits for CVE-2026-41849 already present in target branch (momus prerequisite AllPatchCommitsAlreadyInTarget)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f50c7ad-916d-552b-b35e-b9ea740e442c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:507da4ea-fa62-580f-82aa-2d44b5b43f4b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b300ffd8-5940-548f-bbd0-8032b14a1e89",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:267fde98-e28e-51b9-9969-d2e8d7395531",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789558ea-3225-5f28-8fda-ab0fd632b94b",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.37-tuxcare.4 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.37-tuxcare.4"
    }
  ]
}