{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ece754ee-bf7e-5c66-a182-a7e252144371",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.31-tuxcare.12",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7fcb90f8-0c8d-5f32-a14c-9d78648f9ed6",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:052d605d-b333-5091-b62e-3af9450cd93b",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c8d882-c13b-549c-878d-1c1e5aec7504",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b5c4c1-8729-5925-8634-d5bce0401471",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80c4819f-a9ed-5bb7-87ad-edef21bbfb59",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4d97647-4f58-55d6-9706-b9eb880a4865",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ccddf2-fe98-5589-9f3d-79c424f96286",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2489b7eb-3735-5f62-91bc-da011d58aa7e",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cfdd0c-8667-5691-815d-a1e7fb638e28",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675ec501-8691-57a2-95ae-9e3ebeda1930",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccbf485a-fc24-53b5-8749-dcf1b076e55e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee8990f8-512e-535d-9c51-af2b96b5190d",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.31-tuxcare.12."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe40c1d-41f3-5c20-a968-af36cbe714b0",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca27a72-9f82-5cc0-99cb-7a87a54028cf",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3faab9e0-8b3e-531e-ba0d-bd7f86efd9ec",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c964a5d-9321-52d9-b987-b6fa5483d5f8",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:122f5b6b-213f-5c11-807e-070cc0497521",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4572422c-3317-5073-94c6-cac9f72262bd",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe214b40-755a-5d31-a28a-6cff1a91d231",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3611ead-cffc-5668-8f5f-9075b3321af2",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ceb01f3-d592-5a7a-8892-d7f849cbfefd",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44824e4b-b8f5-5b41-912d-ab0491033c10",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9b0c85-c60b-5fd2-bb3c-3077f666f9fc",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.31-tuxcare.12 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 5.3.31-tuxcare.3) already contains the complete fix for CVE-2026-41840. Both required doOnDiscard handlers were applied via commit 615477c88f (labeled as CVE-2026-22740 backport) merged on May 4, 2026. The code changes are byte-for-byte identical to the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5a819e7-a049-5204-a935-ae1384507ac2",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d80239d-4ec3-5dee-8f8c-a3a6230b5735",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edbfbdee-8fc3-5194-97d6-cd7955871220",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d189cff-2413-5615-922c-0faedb5e232c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e334afa-1bea-55f5-b9d3-bb002ff70068",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a481114f-1044-5f7b-aad2-7078f4595603",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f5fa33-ac14-5fb9-90f4-3329df24e57e",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57aef17c-38e0-5682-82e7-4a9e47cdd39d",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37131f7e-9ecd-5c25-8f3d-2e6857f64243",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac133723-29c7-5ff1-9585-07529e9d77d5",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:533b079f-8ba8-5eec-bde2-0141a1ea3e01",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d384965a-2a30-5cc1-b466-58c970bc0bb9",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fed45ef-7e4c-51de-a27c-08893786b6cc",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e519a684-ea1e-5412-80ad-68d4056edbeb",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:963b9ff6-d27f-5796-a0a6-55cd9ac68991",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0271ed19-49c5-5d53-8804-a5db8336de79",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f07dbb7-8f75-5414-b66f-4ea2c91732ed",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1687ddef-4e4c-57e1-8a3c-a284d5314f95",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4cb86e3-4aa8-5d7c-9f3d-426e83eeb209",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ead18f0a-f7b2-5faf-b517-753b6dbe52e0",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47b99c99-ad0a-5bea-95ae-192b37ebd895",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbead380-1f98-59b4-9f14-616ed08560cf",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b480758-b7aa-55f0-9512-353a19d2979d",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e38a7a6c-29b2-5be7-bc02-ffef796e9e59",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c174cf-17b6-5325-add9-f6a78d3435cf",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb161ee-a811-513a-8bd0-4bcfebf12acc",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39dbc6d7-95c4-522e-91a8-82655d9f9ace",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285f30eb-4bd5-54ad-b3be-125e4fa3185f",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.3.31-tuxcare.12 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.31-tuxcare.12"
    }
  ]
}