{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:069afb1e-4681-5e1c-ae46-e76116436947",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.39-tuxcare.15",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8aed3765-94b3-5c0c-a0fb-c42a9ac43bf9",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acca4918-d938-5eec-b0e0-79db65d3f94d",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-websocket. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c8dd7d6-76da-56c7-a2bd-22b1daae20f1",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edf0ac34-6929-53a5-9d67-f958c12849ce",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6586904-913a-5506-b6fa-6a9f72de52d9",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4fb359-0275-5be8-bed6-c8ed9c905bce",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9145cd15-36f6-57f2-b1ca-789a1ceefe49",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c47db0-1c37-59d4-a09f-189c481f3727",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.39-tuxcare.15."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b3ef1b-400a-5d46-aa9e-eaf47b0afbbb",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97432708-baa0-5c4d-880e-edfc98e21ae6",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8831cf77-3e63-5392-93fe-21a7f32207fa",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b664c58-b200-51f8-88a3-aa6078eb1e30",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d359da0-78ad-553f-9926-9b263517c3b9",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:911e986a-cb81-5093-a3a9-a7dd45185a43",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15571228-b011-582e-b5e0-28345912021c",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4881c2e-80e6-5323-a786-6b4f1eb241fe",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e5bda9a-a87a-5fa7-8d85-509d6ad70fbb",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef16090-c071-5eeb-a78b-2cd43c94e226",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a94fbf91-cb33-57d3-becc-c34a4478dbd9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.15 of org.springframework:spring-websocket. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ac56c0d-6b4e-5d43-8ec3-73fa17b7655f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82985ab1-42cf-5018-adc8-bd5f2537b423",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dfc79b8-ca90-5a53-95ce-44b74f7b41c9",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e956275-f8c4-5148-ae78-88eba6ced8c3",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88261120-7855-5d64-abcd-7be693039c62",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4515c1b-536f-5cc7-a911-d4d9cea80728",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff4bc87-50e1-5858-b7a8-3e6b30b67752",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f0b7cfd-c958-5e4e-9eba-e0f9f6d72e97",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9b19c17-a1ac-5fb3-aa43-b51dc943ede7",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7dbd1a3-7749-508a-8bf8-d5339a3b042b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:670e751d-35b7-5545-bff8-f2119fb6bb5f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:142ebf57-c4fe-53b9-a0ca-11ed2c79a477",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34358c48-f50f-5298-9907-e7c59c9fd13e",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2beadb62-ce8c-5cbf-a75c-cc4bb37beead",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.15 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.15"
    }
  ]
}