{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:691d620c-6ad6-56c7-8120-11c912f7f2c1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "5.3.39-tuxcare.14",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d5370fb1-c1a3-53b9-a146-0e7f1a6a512f",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:378caf74-76b1-5152-946b-baa77364b23e",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-22968 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-websocket. Spring version 5.3.39 is not affected to CVE-2022-22968 as fix has been already already backported by the original developers"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4a97b04-0778-5911-9364-6c5efa5bdd58",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:999784c8-5b04-52de-b90c-c04b5261dcc7",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f0dca3-0d87-5179-948e-ebf103ce5967",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:059f1a4a-1582-5f78-8661-41a22a6360e8",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b780297-3cdf-58eb-8918-458f8ad23cf5",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce03ccde-0825-5167-8806-14af381c9cbf",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-websocket 5.3.39-tuxcare.14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57408648-5317-519e-badd-6b1537f1c529",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41deca7-3eb6-58c7-893f-2e36c0228b3f",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd7578c0-2235-5430-a2c4-78bb68f5e9a1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:551fc11c-2d68-557b-a48f-b4fca2772b98",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:271dfd69-6365-5a4a-a02c-53998bdcef96",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1035296e-4a45-523b-9050-bcd0326e021e",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a852169-81ca-57f6-9cc0-2b4fa824df22",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca7a3f5e-67fc-56a8-aa1a-b6b61236ba66",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec6c13d3-b6a0-5f0f-91df-f905590e2b78",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd93a98c-43be-5ff2-beb9-f066af8feb7a",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e038381-99df-53cf-8052-8e03e905a622",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.39-tuxcare.14 of org.springframework:spring-websocket. already_fixed \u2014 The target Spring Framework 5.3.39-tuxcare.12 already contains both vendor fixes for CVE-2026-41840. The fixes were backported via commit 4ef4cdca34 (May 13, 2026) under CVE-2026-22740, but the code changes are identical to the upstream patches. Both doOnDiscard handlers are present and active in PartGenerator.java and MultipartHttpMessageReader.java, preventing memory exhaustion from unrelease..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03abbd8-5f10-5a3f-bcf1-a9f4025b23ed",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3081dd34-8224-56fb-9db9-760d9131d9a9",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92f30fe3-cc1f-5152-89e6-5f36464fd867",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a88aa771-4ded-59af-8c3b-8f748b3a79d5",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ad173f4-b118-5bd8-8f73-08a7fc7960a4",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dd59ef1-bc45-5f61-a5f0-c43793fc047b",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc868af-f709-5f7a-a257-7dac781298dd",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c671f89-cdfe-5f71-9b48-5d3f36e26c0c",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bd288a0-c9a0-52df-8688-1f7069700b81",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f68695f3-38e8-5242-92eb-ecedcbc69361",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a01000b-90eb-5101-87ec-84046fdacdec",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41851 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88111ac5-489a-57ac-9abb-5504961beacb",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb5c072a-51a5-59f9-b2ff-6e4b71eb4361",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ef3442-c67c-54a7-b050-2ef8d349e624",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.39-tuxcare.14 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.3.39-tuxcare.14"
    }
  ]
}