{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f3dbf72c-64c4-5740-b40e-ec1b55e81c5a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.16-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1fbe0d7a-4d72-5f98-aa06-44fdefcd1136",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d5001b-ca19-5f2c-94ec-d28e83cbb7db",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41234 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3562372-42e4-5efe-9ad7-5105d908d73d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d135e698-4d75-5467-80c9-a146e9a81dc3",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4753722b-09e0-5352-8662-a6b6cc095f1a",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6b708f-2fe4-5c3d-bc0e-8a212315e7a9",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1739170-0e87-536a-9c78-9f4cec326174",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa3ec84-3670-54a1-907c-df0a917bb484",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc4c6a48-563e-5897-a0dd-6ea09954fd5f",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfdeba59-d943-580c-85a0-5eee17aba508",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d26527ae-b93a-503f-b7da-21f6621c00f6",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479cf777-ee8e-510e-8331-4b1c161e0ea4",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4bda530-49e7-5c79-a7ea-db579014ef06",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d45c3f7-8a0b-5f7f-9bc8-ee33f6997644",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11462788-a743-5753-85d2-934957cc82a7",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e220341-9da3-50f5-b961-cabd158f1758",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ded7e5-88f4-5b9c-b45a-711629201550",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ff21e2-a34d-598a-ba42-7856171f33af",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:896b06ab-77c6-5e10-a5d9-b81e9e9a610d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b536e57c-fd90-5145-ad20-5e1824044d69",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bf9d831-994d-59f5-8cab-adaf58be9cb7",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98fc1cd5-0580-51a2-8a69-d882534095dc",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d15abe2-af60-5bd0-9353-e9e2431d3b6b",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f60cf98-4427-53ee-a232-fa03ca3513c7",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:514ff0a2-fb0d-5590-8312-968d9ec0d971",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e143144a-64da-5b07-a100-af4aa58b1a37",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ea2c79-7dfc-5f26-902b-e9c89bdd37d5",
      "id": "CVE-2026-47884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa1e9825-91a9-5fce-92c8-1ad3c8067580",
      "id": "CVE-2026-47885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47885 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd8d30f-322b-5a6c-9120-088b4e0415e6",
      "id": "CVE-2026-47886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d262f834-9b84-5673-a45b-f59005784558",
      "id": "CVE-2026-47887",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:609bbc37-605a-5241-bf54-87f52547b5fe",
      "id": "CVE-2026-47888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47888 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b64469d-22e0-5fe2-8b81-148e89bfa9a4",
      "id": "CVE-2026-47891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:896843b8-9129-5d47-b62a-cfb37170f54b",
      "id": "CVE-2026-47892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8a8cd19-3344-5338-afe6-72550a461bf9",
      "id": "CVE-2026-47893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738fbc17-a0fd-5818-a2af-afb7d9566069",
      "id": "CVE-2026-59280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59280 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c01230f-61d8-5d6f-a39c-393b125b4429",
      "id": "CVE-2026-59281",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59281 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:495be0bc-b600-5d38-8922-edfeca06a011",
      "id": "CVE-2026-59282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2cb92cd-f2e3-5c1b-a642-53f3f15389a0",
      "id": "CVE-2026-59283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59283 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bde687a-4bd3-5a2c-826f-f76e6329e007",
      "id": "CVE-2026-59313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59313 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab11a22-0d4e-5ad8-9a83-603cde0f4b27",
      "id": "CVE-2026-59314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 6.1.16-tuxcare.2 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.16-tuxcare.2"
    }
  ]
}