{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8acb210b-5ef4-5dc8-b4b1-4c6c5f7d1a73",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.21-tuxcare.8",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b93339b8-631d-5ba1-a7ee-2088a5695922",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.8 of org.springframework:spring-websocket. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7d2bd38-769d-5f27-9819-dec0430e9c98",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05094c88-6a69-5990-ad8a-57e140b8b9c3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00cc0227-6ef6-583d-8c23-2f140e1c6747",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c24052-45bb-5350-a70f-bc331f7fb94a",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dce10b6-8e1a-58fb-a52d-cc1bb58fee67",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64b19aa7-8900-5d44-bbf2-27c5ce1d273a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d704a3fd-065c-5ec0-b3fc-510293ff9334",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:517d0364-4f0d-53b6-8c04-e6f23cf0dd5c",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb368bae-8bd3-58a9-9e7d-34344757b0d4",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9342a27c-5649-5f31-83c2-54df91e6f952",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e2ce74f-6cd1-596b-b591-75511f22a927",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc1ff27-7acf-5ebe-acf3-650accf94a81",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:783bd4aa-e1bc-5269-831f-70d1af7ff8b2",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562f85a7-e97e-5d9a-9810-bb536952c45e",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11d64b7-0df8-5932-8bf5-760d8d5c8e50",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f1ea9d-54d8-567d-9fc3-dae968383005",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef4e8b4-dcb8-565e-b044-fa1906a9f6f0",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80f006b-f3bf-5e53-a0b2-62532c5ad333",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee05729e-2b16-5672-afec-1b04dfc4ae6b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6691f01e-0f89-5585-9125-0e42e9b1545f",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4232795-7ef3-5061-91a7-0d1217ad7596",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2238e765-d149-584d-817d-c9254dd6a242",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c19f7af9-63da-520d-b0c3-b682acf6e47f",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f67de2bd-7f96-5660-8db7-976d5c62e5fd",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:127b0089-8c1d-53f5-9336-27b54a0521b5",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96e36f16-f591-589b-9c60-b74232cd5611",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b945671b-c49e-5943-9093-30c8471cf9c2",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:757281ea-18dd-5a8b-ba3e-78a8aa5ec2c3",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ef13bd-ecf4-5709-8d7b-52ed778e67d7",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a99fd2d-ed68-554f-8acb-37383a0ffa99",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb01210-3961-558b-acdb-799314f47a67",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81aec63b-31f2-532f-be3e-af736fcec9e4",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26810aaf-2e33-59d2-9387-75462da493ee",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b3da567-032c-5b44-af70-9e66a7914b9e",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89abd11e-cefb-5fbb-9b9b-33c3b1cb7fc2",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc3e9546-447b-5a1c-9321-f4c964147590",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cee15a82-711d-55a1-ae70-3baac13a3e7f",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c87caa-ca79-53a6-b06d-43f3d561b404",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.21-tuxcare.8 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.8"
    }
  ]
}