{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f69c4464-7dce-5009-90e5-490087c40d8e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.39-tuxcare.17",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:752c63a8-9370-5557-b784-513a138eb079",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:814ce9b8-088c-5be9-b2a1-9f43f3a4e711",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.17 of org.springframework:spring-websocket. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67682ec4-d3c5-5223-b6b6-f8a45be281ac",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b9b8c6f-6ea3-5ab5-a5ae-33f1ab9027e2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf581a4b-78a8-5e46-8307-07e83d6c8d21",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:424bf0ca-bad0-5c0c-af55-2449b77f7945",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c088bba3-3af4-565c-a916-983f2dc40fcf",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370d52c6-fbf8-5c2c-9a73-1479d7ce7e06",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.39-tuxcare.17."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c0f570-c04b-59f1-b0be-8e00678a2ebe",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8b7164c-2f50-5efa-b3d7-58ceb30fb791",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f4e50a-c387-5a7d-8c24-780230ef5318",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c13484c-0492-59a8-9eb9-f2939908f38a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da35663b-62d0-5fa5-ac83-8aba216c32d0",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38629e57-c4e1-5308-8701-8da5d1944f7c",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21fac142-c274-5d64-8c8f-eb1925441287",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d27d3d-7e6c-55c8-b991-a6d9db1726fa",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b0d244-4a08-5ed7-8bf3-f40c73d9a4b8",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa49f34b-be88-5aaa-8b3b-fe28e840d509",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6599d6-9aa9-58bb-b585-36c2752da54c",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.17 of org.springframework:spring-websocket. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96abb92c-3181-5b07-b30d-713b4c829d2f",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599f910a-893e-561e-be19-e50d52b69241",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:656f5f95-6d3d-5dd3-a685-ec0c9af7229d",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bf916ec-ac13-5dd1-8dee-5448f40b0eb1",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06fe6af-1d91-5a89-a084-c1edb0a586d8",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d49be098-8619-53a2-a94f-22c8a4ca925e",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c8e800-69c5-5dbc-b780-9fbbb5eb0940",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea683575-d6d4-5fb0-a2cf-983e0b192fe8",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebfa08d5-d1cd-5b7b-a5d8-7bd6a59dd5be",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ae2937-7566-5d26-8555-6ab5f0cb1ba2",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8475a6a-7cf4-5ab0-8873-85964647df0b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a2ff17-40d1-50a5-a639-cfc0a9b5a9bb",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebaa53c4-6a0a-5788-845f-a93e5d1e813b",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285410fd-f459-501b-af03-0992ef954b38",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.39-tuxcare.17 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.17"
    }
  ]
}