{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cbbe0089-26f4-5057-b94e-e1bc2911dbe9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-websocket",
      "purl": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1",
      "version": "5.2.11.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c81c3ba-c30c-5f2d-b4df-993a659b3c97",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b88811fa-5728-5a5f-9424-b93afd86444e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ce82413-4aed-570f-ac44-3a066fd463a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9797386f-1fab-56b9-8a91-e16d27044557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22118 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51f11804-cab2-5878-90b6-b53b01f4a0c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ca824aa5-7a8c-5dcf-bf9f-2f372b7dbb78",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f47aa25e-bdf5-5734-8613-55cb5062afdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a3bd3de4-08ba-513b-8dac-f5a71f0ebb4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1cefc09c-3a61-5dc4-9680-7dbbec566104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea268b31-c075-5705-bd7d-c3851530dfab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b5d1284-0425-5737-b1fe-66beeb054ed2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:487f9ba6-3393-5951-8c1a-862366cda0bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46bbe79a-6e3f-5dd5-9980-417489ef4bba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3e6a25d7-515d-5fd5-bffe-2318dfbd3b06",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aedf82ae-d64c-552d-bc37-4b8872951438",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54170080-c6ce-5cc6-b98b-d48592c4a4b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:41b20c8e-881b-5243-b3db-ee568f1b2468",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5e2d5609-9e66-55ca-8679-9186a29a3307",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket. not_affected \u2014 Target version 5.2.11.RELEASE does not contain the vulnerable code pattern from CVE-2024-38820. This CVE specifically concerns improper use of .toLowerCase() without Locale.ROOT in DataBinder's disallowedFields handling, which was introduced by the CVE-2022-22968 fix. The target version predates that fix and does not perform any case conversion in setDisallowedFields() or isAllowed() methods. T...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa1a6b39-8838-55ce-af07-2589728f35a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75c0f012-6ed2-5cf8-a161-fded04755658",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d356893-ae63-5af3-9bfc-20d06832f097",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a423538c-9b75-552b-a59d-a61cc66143b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:da9641f7-7684-5e76-9f28-d2628045ffda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2abfb4fa-dc0b-5a33-bd3d-878eee95a96b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1406e382-9064-5f8d-b3f0-64e6fe552b50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02c9a86d-e90d-53bf-9a22-e664dca009ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6efaebd1-db2c-5dff-a4d7-d14f2abe32fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:faf0759b-733d-511b-9365-d67cd1164fdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cd618e53-3bf3-5b4a-8e53-39872f244695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e687e4f-7b81-54fb-b980-1264898dd5b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac54e978-d95b-58cb-8fcd-30e6bb2cbd03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ee677a4-95fa-566a-a6ad-6eb68106eec8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64a1b6b4-dae6-5fd0-8991-9626b4172eb1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:43a34980-1e86-5229-a2ab-5e4fc0acbedb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2110f041-d58d-5b3c-bc9f-5ebaf99b2d37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c04c9b2b-a298-5859-835a-d86af170127d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:378cf47d-f083-5301-9292-89ad384105c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bbb955d1-26db-5342-abcb-1faaee923815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e229a84-b854-5c92-a240-1bed9ec384c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ffff9065-5655-5fa2-ba24-271291f1a411",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:37114c8d-205d-57b4-a50b-3b72a3272891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7c839a6d-0e0c-5447-a5c5-0156d8ef3f27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4db7b25e-4473-56b0-bc8a-41a1c38be098",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f7ee928e-9836-5b86-84b2-d70d0961bea7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a575d7b8-9b52-5438-88d1-ddc91daacc26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:214c69fb-d0a2-5e9b-b661-d36e916b0b1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47884 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:670956d1-f4d9-512c-85c0-19ce6201130f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47886 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eeef43a5-722f-50af-aa39-e25184d6053c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47887 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fd0e5aa0-d18c-5920-9fb5-38db98a58918",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53a6cf35-54a9-5570-b3cb-b3bbe71a0947",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47891 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:717413bd-065d-5a09-a580-cd6c9b8ad895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47892 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2f4e3d12-4870-5454-947c-6b3fe699cdc7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47893 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c435f7d-5f94-5141-97f3-dd99a2017e65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:59c14c7e-1783-5a33-a381-8a82d169af65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ff99176-33e7-510f-b8f2-7b52713b7cc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59282 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2324e51-f4c1-59d6-ac1d-76dbec5b15f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a4b3ba12-5f71-5a89-96ad-18a9ea8dd7f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59314 affects version 5.2.11.RELEASE-tuxcare.1 of org.springframework:spring-websocket."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@5.2.11.RELEASE-tuxcare.1"
    }
  ]
}