{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:33d62e42-b18a-52fe-8bfd-8fe14fede14c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.29-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98314d30-99c7-5893-a9c7-59f83ae8bda5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec7bb3e-5c1f-529f-bcef-fb2d60d2713b",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49f6507-67c5-5512-83b6-acfacc500301",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0e40da5-9391-51f1-abb4-af84037163dd",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708a887b-420e-5829-b1ac-2f116c1aca69",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2477a5a4-3669-51a3-998e-988157719b28",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4803e89c-b96b-533b-94ee-d8ce79c5a21f",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e79c22-e979-5d65-a934-8fca087242fd",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a196c81a-d528-5c17-9e5f-ed15f66d3e7c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16e25d83-be85-5736-89ef-03cd1732cdaf",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e295cb36-4103-5485-a5e4-d15ca47a913f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d22916-6752-5dbc-912e-6d4b5305e79d",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.29-tuxcare.8."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce8112d7-aaaf-5e8f-98b6-67f262630bc5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28d8214b-5d38-559a-8934-dd9462770514",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d320491-9a6a-55bf-a2cc-dae0a3542d83",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60bd582-0618-53bc-8432-2cf07c2e409e",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50586435-6ed9-56bb-97fc-512856eeb5b8",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a71aa37-7fea-52bd-a337-8652df87e655",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c834cf08-699a-503b-8d87-76cf92c7aa67",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fb81234-2878-5188-aa20-ac3605df0a7d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46be2010-375c-55b6-8559-f875587f8400",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e047a3-62f4-501a-9da6-ac4b107f0a91",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d46c8736-426a-5c31-b488-706c74836b91",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.29-tuxcare.8 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.29-tuxcare.4) already contains the complete fix for CVE-2026-41840. The fix was applied on 2026-05-19 as part of a TuxCare backport for CVE-2026-22740 (commit bc0026ae70c), which addresses the same multipart request DoS vulnerability with identical code changes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89c456b5-ed95-5157-b734-199a931b43e5",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:116c5725-74df-54af-bd8f-08bc4c3a74ee",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c23112-8757-53c4-a31e-bded25e452fd",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:698c61ec-d0e8-5702-9f6a-247b39c8cac6",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e13e2e3-f419-5816-bbe7-64b10f66d2d5",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a57e344e-ccc6-5ff5-84dc-7800179cf496",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24203e0f-2e97-5da2-bfe7-efd08c6276d1",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc3fece-591f-5e63-b49d-aceb03e4afe0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:effb7a14-1488-5e47-9368-921ce2125e51",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8af2aef-8482-5338-bb38-672b06606e46",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95609bfc-9093-516c-bc79-b0ec1aa0c953",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a2eae10-d002-5876-ae99-d3fad6657d10",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f851a1c9-7ca2-5013-8325-1ded0412072d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ca80ef-b1cd-5553-8cf2-c9fdb79dbe1f",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ea239c3-045b-5aec-82da-e6ae84b544a7",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518d9228-0633-5b30-b2e9-e08ed12df001",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb2d563-14fb-58a8-8ca2-b17e9cb36b16",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db0467dc-638c-54ce-8649-a26394c6831b",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12127037-492d-5dd4-ab23-40f5b07a73c5",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:342b87d0-6c07-56b9-9c09-74aa4190e17b",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245a9465-a437-523d-b63b-372229281db5",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:407be3b1-46be-5722-a8d0-9985801dd8ce",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6567758-6889-50fa-8473-4cd95a827f85",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab47d197-972b-559e-800c-fd549fb1e647",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b59bf571-20ec-5c61-97df-60c68d798021",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25ad4fa2-07d3-51b9-a924-82161ec3e16b",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cdce615-ab4c-50e9-8253-825b11ddffbf",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcbacf5c-53b3-5b00-a502-fd77763c9fa8",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.29-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.29-tuxcare.8"
    }
  ]
}