{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d4f9480f-81f0-5691-8d02-f0fb89f2d2c7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.20-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b6469c3d-6d3e-5558-80ea-fee01fddbf4c",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.9 of org.springframework:spring-websocket. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f53024e-63a8-5f19-ac2d-81fc2e175c16",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84905c70-7d75-5297-872f-693e002675fe",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a129c97-b29c-5f1e-8adc-bbe5aee9acad",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9836271-2cc5-5eb3-add0-2e916563c256",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffff7ded-7ea6-550c-afea-a0090c622b2a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17986e22-747d-558e-8628-9b20b5ecdf40",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45523365-7da4-5162-a9ec-7c3d052f6b21",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82151dc7-b320-5b46-a083-cc8d00b8a373",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aac62751-ffb4-52f0-8aef-8acf7b646b7d",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0121b93d-16e8-51df-86ee-320aee717331",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d360e1a1-0ec4-5946-ba0f-95e6f0ce5c01",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2957525-f3c9-5ef2-8970-108c7c187b9d",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da490365-51e6-5ae4-9d62-6576708a493b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62104659-d427-5aac-adb2-d1a78a61e1bc",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba7265e-f493-51f4-a62b-e532e2b8f915",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1f13aa-da6f-5506-afe9-c2aaf55e8682",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ebd312-c86b-5054-bc85-4fe47362dd15",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76fadaa6-8d68-5569-b7e8-17513524295d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11cd46de-bf7a-5dfb-ab03-8515797f7abf",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce56863-1c43-5d84-8a82-3aa428e3430f",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f095def-8e08-5d83-8cb9-bd54b6cfaadc",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c2e2fd2-228b-5f18-88df-f14cd797330f",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c08be944-e8c9-5e34-84d3-11c275042fc5",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0f59a22-fe00-5ecb-a17e-ddfc274ee2bf",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41854 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e568c007-be07-5d26-bda4-6e4dac7aa55e",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf15fc75-14f0-506e-b044-042a6673d664",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b1049f5-4677-56eb-a810-e5b795bec5ed",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47885 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16aafd46-e1f9-5f16-9b09-10d2bdb215b1",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8b04fd-4ad9-590e-a4df-6534df920288",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c9147db-1985-5129-ac5a-0c1392e8ae68",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90da4c96-6863-5e53-b4a0-40ad33cfaea8",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82bedcd4-17ea-5f77-b7d6-42d6bd15c79c",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffd52eae-34f5-5a8a-8e0e-9c6157f06ed6",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d66a721b-a4b1-5222-962e-5a0603a15dd4",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aedb086-f537-5ce3-b25f-dc601d2fd079",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b32146df-9675-5e2c-9b59-7cbed6f9927f",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fad2a84-676a-5e21-a5aa-27a397fc73c8",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ddbe4b0-7917-5e30-8554-6f2a6233aadb",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff4d2d6-6c89-57ff-bb6d-3325a5ff5213",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 6.1.20-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.9"
    }
  ]
}