{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:744b7eff-090d-589b-9ab2-e668dda7b733",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-websocket",
      "version": "6.1.20-tuxcare.7",
      "purl": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8c530ac4-326f-5066-8eba-9b19f1839d16",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-22233 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-websocket. Version 6.1.20 is not affected by CVE-2025-22233: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1865f282-470a-5c81-bbce-0596e30ede96",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d45cda0c-1949-507c-b8b1-eef44e4d5a19",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac44bf1c-4024-55cf-b4e6-6edd51bf8444",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d367fb74-004e-5a84-9ec5-a4657092a83d",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0415ca-39ea-5dcf-ab58-741b46314f40",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:decce1e8-8baf-5157-b08b-620a9cff23d5",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49959fce-ed52-5b93-84a4-469c8bf4fbe6",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:190f299b-f5de-54f6-8033-94ebf1c191c7",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f8be460-8f4a-5b4b-8708-5602d4f74c98",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a5527da-5d6a-5d3a-84fb-73b227b33902",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4c9b01-6924-56e7-bcb5-adecb76e1b28",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff65222-70a8-59f4-adf6-c2fdaac0cf69",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 6.1.20-tuxcare.7 of org.springframework:spring-websocket. already_fixed \u2014 Spring Framework 6.1.20-tuxcare.4 already contains both doOnDiscard handlers that prevent the multipart memory leak vulnerability. The fixes were applied via TuxCare backport commit a6b78f2a1c on May 19, 2026 under CVE-2026-22740, which appears to be the same or closely related vulnerability as CVE-2026-41840."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12c6d3da-de9c-5b18-b72b-2ebf21e46cbc",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db402c9e-55a3-5eb7-95ed-4874736de004",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41842 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:658ad984-fb0c-5a37-8adc-796ecfcdbe24",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82d31229-b4ea-5c88-82e4-1497ff8e45cf",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a578c1ef-86e7-5781-bae2-df4ac9a7be0f",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3cc44f0-a275-5c2b-8691-24d287e72175",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41846 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac6a5521-d394-5a24-a730-8ceb29b47a3a",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41848 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faef123b-d4bb-5ea6-9b97-c26171907fe8",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41850 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:900ddfa7-3296-586f-b90b-a5d02d76d1e0",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da0fec5a-ecde-55fe-8797-b91c51947ba3",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41852 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c569615c-07cd-5438-aec2-5bbe431a2d81",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41853 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee268042-d174-5aa3-a9b9-68110d1e1d94",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 6.1.20-tuxcare.7 of org.springframework:spring-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-websocket@6.1.20-tuxcare.7"
    }
  ]
}