{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ad1d3ac5-595e-5e86-95b1-455a4198cac7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.21-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7b7e44b2-7383-5103-90aa-626bf9813a98",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9c6a05-a099-56fd-88c4-af689dbef3a5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12ee6af7-466d-59b5-b5d2-440dbeee3f77",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79fee28b-0593-5445-8e01-cd1f694cee23",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a419fe9d-6661-5001-ad9c-5c5426c657be",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18df626f-6cd4-5879-9ef9-66e6583f4e5b",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10cd215b-9bb7-5c14-815d-7772d7b47764",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9115724b-1b0d-56ff-882b-db088e199e0e",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7321d85-706f-529e-8efd-8b4fb7d027db",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a18edb7c-809a-5a73-9a30-4d16956c264b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5754313f-c450-5cb8-b1a0-8f28be1c07d3",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3b35bd2-40fc-5b54-bda3-8901c3450fe5",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.21-tuxcare.7 of org.springframework:spring-websocket. already_fixed \u2014 The target repository (Spring Framework 6.1.21-tuxcare.6) already contains both upstream patches that address CVE-2026-41840. The fixes were previously applied as part of TuxCare backports for CVE-2026-22740 (commit d8aa04a97f, 2026-06-08) and memory leak fixes (commit e7c90921fd, 2026-04-29). Both doOnDiscard handlers are present in the current code, preventing resource exhaustion from multipa..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82be03e0-860d-5848-99e2-b047f7e48d97",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b08b1c7-7633-5ebf-b5ad-833728dcf4a6",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d24698c2-c2c7-5721-99d2-2a461f8ee447",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44fd6778-7234-540c-8d80-68a10e307270",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0270de34-3cc7-5c99-825f-b352183a215b",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73fa2ba2-bbbf-5109-a280-d714a6114c2c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:725f2458-9665-5fa2-a753-efab6093fdcc",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a037ca0-3a77-527a-9759-6c542a04cd17",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:117059df-aed5-5319-a533-83447e8baa5a",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e71006a-a01a-510b-9a8f-1fc5e5e2bdc2",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fdd3531-3d97-5b6f-a528-10237a863d2d",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceced881-6029-51fb-9128-432510674bdd",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.21-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.21-tuxcare.7"
    }
  ]
}