{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:321d948a-2a97-509a-a1fc-054f1cb074cb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5",
      "version": "5.1.5.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d54d2549-69dc-5ca8-b958-58590af536c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3c374dce-7f31-538c-b9ed-7eaac9c45e0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:306ac5a5-c7f6-5837-abe4-fa94c5cc6184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ed1a857f-318f-5a78-8461-0e04984b8f82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:358583ff-1027-5ea6-b23c-ce65101e7c66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:71c9e28c-7159-5775-8375-4bc77d9807bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5e99edf2-554c-5f9f-b75f-26c6e2f4b7a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5484aa91-f0ec-5a48-965b-a87fc8ea4592",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7e93b403-7104-56d1-844e-127e55eb7adf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:06348e99-0ed0-5c10-a922-d828e01b9206",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e92f4544-b115-517c-8e3d-d0757eec5a7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1965f14e-a25a-5020-b1cb-48a063c79268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0da3ec18-73ba-5130-97dd-f1ce9f9ba0d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dbd09b96-69b0-5b10-9b94-0f48ab094bf3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4c6efade-ac76-524f-8b65-f8c09ba2ecb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7284701a-13a8-597e-b121-6ddf5d9e5bfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b7e06b2-ee84-5ecc-9963-e63badc903a4",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-websocket 5.1.5.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2878de30-6f38-5257-9455-c804e4ca1f07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:36715ee3-07e2-50aa-9d44-7b20e77d7a94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3b766b6a-ffbb-555b-be89-14f868192145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38828",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7bcb3d1a-0449-5989-80f5-5305dd44076c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:35fc4d32-6a2f-57e3-88a2-e74da5dfd130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41234",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d028b2c1-32d7-57b5-b9cb-07d28c5df1df",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-41234 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket. not_affected \u2014 Spring Framework 5.1.5.RELEASE is not affected by CVE-2025-41234. The vulnerability exists in 6.x versions where Q-encoded filename parameters fail to encode double-quotes, allowing header injection. Version 5.1.5 uses a different architecture that only outputs RFC5987-encoded filename* parameters (not Q-encoded filename parameters), and RFC5987 encoding properly percent-encodes double-quotes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:97c0ad77-0464-5de7-844d-ea9985dc9220",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a02290a5-5995-56b1-b740-1687fbbddffd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:553ad332-8b58-5d71-9022-16aa47144cbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fc36a176-bef1-5817-b851-2f623f0ce223",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cca70cf1-ac70-5d5a-8f55-3906a2fbc31d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:291293d8-fa2a-529e-be96-e40d1b7c8f08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ad9f8b5-70cf-5443-9b52-200f8d9455d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:189aaf2f-4310-50cc-88f4-e81a56ca2516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d0b211ee-a86b-523a-a303-1f3c19e6c573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5bc653fd-f86e-591c-8742-f7f018e35c1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:13678790-1486-5451-a9d1-97662e6655eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4a17eca0-358f-5f93-9ba1-458086d727f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4a52069a-49e9-534b-869f-1289b20e27fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2aee469a-3a79-5cf1-aecb-c86d887466bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9a77d97d-3998-584b-a071-544d7b2f4bf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:df2ee792-dc52-5672-a03a-2e4322440601",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:55d2a7f6-6101-510b-9674-c796206e6fe7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b057c0b3-cd35-5312-bbb5-f9ba94eb5199",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41847 does not affect version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket. Spring Framework 5.1.5.RELEASE is outside the CVE-2026-41847 affected range of 5.3.0 through 5.3.48 and does not contain the vulnerable RouterFunctionDsl.filter API."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3954ac92-eb51-5525-b452-90390c30acac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ae188092-b4cf-5d6c-9c20-b7820052b07a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9e478359-9705-5e4e-8ac0-fc643c6ea560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b422c5f8-2a5f-585a-96a0-821e1047d4cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1a933b28-96d6-59ab-8264-9af296a549c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a1973dba-0fbd-598b-b0a7-21c3f9e51c05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0d5c3aa5-190b-5697-9db3-f3091d695e1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1dc9aee7-3520-5e22-bf52-73e804872bc6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ffa0a8f4-5c18-5ad4-9326-32600283f6d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5e5d391d-c069-51ad-93e2-2ce2a3bf91b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fab12af6-44ad-5ffd-9a51-68b266750dcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2317b0fb-2208-506c-8cf5-425e978d9acb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0a271098-5dc1-515f-b8af-7d57eab0613b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:70c248e4-636b-58cd-9b57-bdd1b574b19f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cf7be8ad-45fc-5c89-99a1-b4ff4f8b2cde",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a2cd41d6-d47c-5271-8911-542f01baaf09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8ecdc0c9-bef8-58ab-956c-07fa8942d8ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1c12c4fc-b4fb-5ddb-80aa-f156b83f37d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.1.5.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.1.5.RELEASE-tuxcare.5"
    }
  ]
}