{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a3898f78-5a92-5f3b-beac-e3392aa5999b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.20-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:76ab54af-3ac2-551d-8467-935a0f8b362f",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.1 of org.springframework:spring-websocket. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4232ed8f-aa74-5f0d-9ed2-269a1eb72e0e",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e6e8e7-6941-5897-94af-d206cc27e41c",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b319a2ac-5461-5cbb-8f4f-6fbddac534b4",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4cafb5-6092-5048-ad09-579ef9a6ce39",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a5f3392-0de9-5acf-967b-7cdd933f80d2",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00f8fe0f-fbba-5884-a877-b5371a16f25a",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:584515cd-0b9e-50a2-a576-a08b163a18c8",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0dec80c-d0df-532a-8d5b-2c9f7667cb5f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38acb36d-5aaf-54b5-859d-43eccac3ae4f",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9887fef-0e3e-54cf-8e55-d28c59832eac",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f26b68-91ba-543d-9faa-44c3611c5f61",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c930022-0f35-53f6-9d38-d6a684f585b8",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d371a138-1f37-57e7-bf45-a96d3f7eb6e8",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfa56dec-c5bf-5185-8e91-8cba73b621a5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:809897d1-ebbf-5360-8f98-2e3a7b528c52",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed79215e-d010-542c-bbde-a43ac4e77f93",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4849d07f-c60e-50cc-a097-68d78c2d6274",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b8b610-b843-50b8-8978-bc5deca8c0d5",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc3ea810-7f53-5496-91a0-a387c86caa51",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e48ce30a-c213-5b88-9220-f01b1b5d198c",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76283a22-65d1-52fa-9301-b6c710c6975b",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a73ef05-e9c1-575a-9622-9ce5c14b90e7",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:258793c2-23ab-557a-93e8-81ef314f4c87",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c1361d2-8745-5231-bf52-70fe7a559602",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba6fcafa-ace0-5933-9082-78c22f00459d",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d3adb36-9c39-5ffd-96f6-85d6eb62ac14",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a99bd5-44b7-59e3-8e6f-df25cb3c0bdf",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc11bc5-3548-5084-b163-948bef5b6d0b",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c8674c3-67ef-520c-9de5-a6f818ad1f9d",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:410b9c76-310f-5530-b4bc-571e457b0d6d",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ffb363a-31bf-514f-8a8f-13da328c5284",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e9f16c6-634c-59fc-bf61-b3297816a889",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f7f1454-f99b-58d6-b0e1-55c28f26bcf7",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3be6e2c-a09c-5898-a28a-337ca7efb006",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe2c956-e358-5355-a4e5-ccc6d6743b68",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dd52ce6-9c13-58a0-9462-ef89daffff19",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0ed6ff-fedd-5b32-976f-f6618e9aeadd",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749ac252-e01f-5ebf-a65d-3083140d47cd",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1059076f-be41-51ca-9bda-9c799f1c165c",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.20-tuxcare.1 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.1"
    }
  ]
}