{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:29d139b7-2f21-53d9-ad2c-094ae31b3af4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.27-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a9080ed3-dd2a-5449-a611-8851a7733255",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:633a4d62-6797-5b24-854a-f31b8b61ca08",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf8f5dd1-9a99-5c7a-a0c1-eddb99893223",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02d34f98-2a49-57f9-93db-a67212364842",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc3ff647-d400-5b0c-b48c-f35efd0846fd",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:995bf688-8f27-5495-bfd4-cccf8f385798",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bdc901b-4959-5adb-a672-20b894046356",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eba7485-ec27-5c7c-ade0-48b2779b11fe",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5083131-f9dc-5d77-8e6b-d6f660ca2cbc",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf8666a-cd0c-57d5-9826-56ed0bd2cb73",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5856945-05e7-57ae-a655-135f5080f20e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08cdcf57-7923-5f63-89c5-13bc5139cad0",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.27-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4106c66-c646-5d70-9cb5-cfcf16e9768f",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:379d53b9-fc64-5c4a-90dd-2f2460394e4c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:540f28f6-a175-5876-a20b-6739a37e5f4e",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81774150-3db1-59b5-9b4c-5a7452089eae",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9558f49a-062a-5eb5-b310-cb32af1024d4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6581807c-17df-5215-80b4-a68dd0490ff8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f50792-4f78-541f-be22-3288ee291bd3",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8999950c-a575-5559-99ae-2900b549820f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f787c11e-161f-5c52-97dd-c4db078339ef",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e19c15-022f-5b12-9a56-a29debf8a4fb",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9b92135-75d8-56d2-a18b-2ba38c0b656d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.27-tuxcare.5) already contains the fix for CVE-2026-41840. The vulnerability was previously addressed through backport commits for CVE-2026-22740, which applied the identical doOnDiscard cleanup logic to prevent resource exhaustion from multipart request processing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:615ab53c-03a5-5431-b5c4-a5affc170142",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ffcb4e6-7900-51bf-bc3d-527ff61a53be",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b88e770-75bc-5d65-aca6-a1d58ae4e1c8",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3daa7700-e125-5fa9-becd-ca214bf695a0",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a86b3519-bed4-5fc2-bef6-d66edfe753be",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4326851b-4f5b-5106-b5f6-2cde01513445",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4263fe3-f86d-5565-85f6-3aa877d0f3ed",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.3.27-tuxcare.8 of org.springframework:spring-websocket. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:519abd32-e8e9-5295-9806-fc48b5cc2d65",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2eda183-89bc-553c-a2d2-4a5ed05ec7b8",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b24ff9-10c6-5014-86fe-86e37e859e19",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04073ad-16d6-5227-8fca-3868582bf622",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956671e9-0703-5896-a4b2-c3a21d98756a",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f190677e-231b-5b3c-8f41-7da5eb6d8c66",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9335f82b-61f3-5313-ac21-bfb25743bc24",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c08c3f4f-e11b-5191-b553-28bba6bcf007",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb2ff1e6-0350-5132-b827-713b880fccc9",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2abf1d0-6308-555a-86a1-f45e496ba930",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51bc7263-ea7f-5e58-98ff-ffa603931780",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e5ca8e-4a68-581f-a68d-2098af1d8dc3",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9ac243-95bf-596e-af1e-fd3b7afe631d",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c5f991-7e4e-5550-8043-1372be49844a",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bf5b470-4f43-521a-813f-c9f22860be13",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ae9f359-6f78-5e17-96d8-0ee04f866e86",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245658be-c539-5201-8818-689b5344ea6a",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f69e2c7-b328-55b5-9f3f-d93b3327f6d7",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7521260d-ea69-5676-8add-2da735ad4442",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d497fe-842a-57f7-a9b2-c6a23ed12f0b",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfdd96ec-defa-576c-851b-3854157c7fc8",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.27-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.27-tuxcare.8"
    }
  ]
}