{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a017ee0e-a0c8-5fc4-9395-01381cb752a7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5",
      "version": "5.2.0.RELEASE-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:462b614d-2c85-5478-9ad4-2c3df22f571a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2020-5397",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:224a2747-8fea-5dff-8200-f71d1baf9989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5397 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2020-5398",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:65b6f9c3-4145-54d0-ae87-f127c493113e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5398 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2020-5421",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0444532e-5aaa-5fae-91b1-3824f5abab43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-5421 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fd38627f-d8a9-51a8-a9c6-2e5349a5510d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4de81c7f-473c-50fd-be40-c8bc4214b984",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22096 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2281f291-a593-5eda-8354-adb3fc4afdce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f81450a1-8da5-53e1-93d6-046dc2f475ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:94ea9183-a297-5903-95ab-53f8e67c1640",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:93b64e44-d00a-511f-873b-00d5463ee356",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:160fcc8b-d3df-51e0-8f39-84f1b2f4690a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8e57ceb3-3593-55e9-959a-19d8066c8699",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6670847c-a244-559b-992e-c4d99f2bd024",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f293229e-adaa-5371-9a85-6f9a771daa6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eddfcdd8-6d80-5db1-a8e3-8a36c128c0eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b75d82e6-8221-53fa-81c3-caf1dac6d7eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:24486c7c-e1d2-5ba5-be41-a9778dd77f8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e1bb55e-4333-5632-9ef6-d692d6fa2220",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4aca3752-2bf2-5c1f-b552-3048136047ea",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-38809 is a false positive for org.springframework:spring-websocket 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4b7566fb-07a1-5b51-aadc-48b0587322ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c14bfee0-648b-5daf-b460-d4c59b30fbdb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:359c8314-378e-511b-b0b4-09df38a0e026",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a813fd2c-7e08-5c51-ae91-bffc679a0eb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:99107a12-0411-5292-b84f-6b4f4bd097b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2195cec7-5a09-5d1a-b154-4ebf95603349",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41249 is a false positive for org.springframework:spring-websocket 5.2.0.RELEASE-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3d8c985c-ebce-5595-bfda-24b904582150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b8e31a84-8319-5a16-bebf-7a9acd070402",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5a74e144-a17d-5c63-a54a-fcea9bae1af9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a9e84ec3-a53f-597a-a026-2d339025121d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e930e186-cac8-5e27-b9c6-a250e697a800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4e854a1b-14cb-54b3-af37-853189b48a4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0d0d8cc8-b1ce-5080-8ac1-a7c3d8b830c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f5dda6f3-f6a0-5914-9860-3f637ec4c4eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9ea14544-e2e5-54e2-8324-9ae5c28cb25b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:29b0dd87-b75e-50e6-8321-9932dbe14dc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8123be26-3766-5d34-a55e-d2db19930816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ec5f2376-f6e7-5746-9ce6-666d0ca7360f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3aae97ff-3ecd-5ba1-a87e-bc8ae40a1c78",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9ce82460-d93d-5f4a-914c-5942ddfe77ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:de091b71-11be-5139-b7b8-1a52b7b00ad5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4bb4c1be-346f-5756-87e3-28bbf4c23238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41847 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:52cf01bc-f4f6-56d0-9b65-2c177b1e1fc8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:104a6d7a-614b-5c0f-8154-11864887fc6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2af37f7e-7b18-5e35-8864-a325542685df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b1df760d-d905-50c6-a4ab-ec7dd7236f65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:47b59c78-686b-5c20-9458-9199ec363696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:92061c70-a7a8-50b9-a466-f6bc1124da88",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket. not_affected \u2014 Target version 5.2.0 uses a fundamentally different multipart parsing architecture than the vulnerable code introduced in Spring Framework 5.3.0. The CVE-2026-41853 vulnerability affects the new native Spring multipart parser (MultipartParser and DefaultPartHttpMessageReader) introduced in version 5.3.0, which does not exist in version 5.2.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a1e23681-f9d4-5b11-a917-1de939d64275",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3cf13da9-3c96-5b0a-a2f0-1147b6bd469e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:03d6060d-05b7-58e5-a960-a16e0b2006b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7ea3dcc2-21e2-5956-9533-ee33644dd700",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:88d5c03f-adf4-5e41-a069-ad055a0694fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:34f26bc4-4163-58a0-91d1-688702196159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cd886103-7aeb-5a4d-85f7-bddde50aa391",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0dd3b72a-7505-5ca3-928c-4f927c43d352",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ca2a095f-88b8-5a73-ad8c-4e50b30c2c2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:25188e5f-2a45-5736-9998-021f00667189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e20e0fc8-bd27-55d0-8ac3-0d0903e5fdad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f3e5e1bd-de73-5f20-a0a3-54c2294824ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3643b5b6-9af1-5423-853f-0878d9b64844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.0.RELEASE-tuxcare.5 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.2.0.RELEASE-tuxcare.5"
    }
  ]
}