{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:27ff97f5-d8d5-52a7-962b-c3fad48b7e6e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.21-tuxcare.9",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b459a2ce-70bd-506f-9099-9a7feec95ec0",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.21-tuxcare.9 of org.springframework:spring-websocket. Version 6.1.21 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: ee62701f5634e904e42e218baad142cea2bcd332\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:864c0725-5442-5a70-b0b9-4671f4457153",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:723d6bc1-0357-5568-8b5c-2527c5e78d1c",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39cbfa10-bdb6-5e46-9d18-160a0b077c85",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e50eff-5a69-5269-b313-7612b2b47892",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c72789b-f922-5db1-a303-81b32a15b6fe",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6df29e-a5eb-58ed-9c29-b9a04ed87f0d",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2435c03-07aa-542c-9c34-fcfc904aabb1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cca4e36-f3d5-5754-96dc-256a3d5f2338",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a805f6b-dfb3-5106-8805-d193a09d1c4b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:594cab81-19af-5a64-8291-2321112ab2b7",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdba0da9-a552-52d3-b18d-1bc787aca1b9",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c15837-608c-524b-8c80-b62c0127435b",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70dc5549-2cde-56ee-8044-5e6f06ab762d",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76730e22-3878-5f0e-9863-811adade7b5b",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41843 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a711a9a5-4313-5708-8ebe-2faa881bfe7f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eda4289-2a76-5a0a-a3c1-4cbf9e2c282a",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc23ec48-efd3-5def-9441-a67d0a0ce299",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bbdd34-5565-5133-86b8-4c79f7333639",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92d65b5e-0690-52cc-b63e-d2b84d716ba9",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b259da64-1e3e-5735-9e19-5529bb14cb3c",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74bd3d0-b198-5446-ad9c-6fd198980372",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b27df8d-db7b-531a-a570-7133f47c1a70",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1780e9c-3d36-577c-b7b7-62fad4f36d4b",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f3d406f-4734-5b48-ae81-759a879059b4",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47220532-4121-58bc-b559-a7801728531e",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef6fa266-d52a-5165-9b48-a8f96c2886fd",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7530a3c-30fb-59c3-80ea-1bb25b62aada",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2050e6c-bc15-534d-9b60-b46bdf7f24e0",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9900a408-ac85-5448-b2d2-8df16bd02817",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4a4e543-81ea-5307-b44a-6409c9039dd0",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d82d7f-04e1-5be5-8186-f702bad900f8",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ad9934-7cf3-55b8-8500-8ea3daddf838",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56894f38-7068-570f-af8a-e2d3cb83cb18",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cb6db82-a648-579f-9350-c07061ca301a",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3fb3b7a-4dec-57bf-8b2d-758df19f3f1e",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58e644da-6693-5421-b6ce-87715bf070dd",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bc41d5b-0011-5a47-8501-fa4e4e006a67",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a47210-b254-5ac8-828c-8f71fcb3bf48",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.21-tuxcare.9 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.9"
    }
  ]
}