{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b09745d0-b69a-55f0-a007-302aedf85b9c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.services.sts",
      "name": "cxf-services-sts",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fcdc3882-e0c4-559e-b1d8-7d53a8315626",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a69d5d-19e5-5f4c-9405-89960740d449",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91403c28-ee5e-59fc-816a-719b4b2d6a10",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c70b12c-b11b-5a4e-90b4-89425cbec6a8",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913ce2fd-4f38-57d7-82a9-d934699e0dd5",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0e36bfc-01d3-5b30-b783-99d16f033a63",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a643b426-b057-5e63-bba9-b81d4160c11a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1151d933-89f0-5d88-b77f-0fcf06540f1b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0b30e83-9b2b-58c6-8868-3c942a6e6210",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9699987e-bf65-59d8-9bca-4de11f7fbe53",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4cbd3f5-39b6-5960-80f4-47189e5fed40",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acd431e6-77cc-5b2b-b40a-ca860804edfc",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c096c2-1bef-5f6b-bd13-ee28f20df132",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58cd97ed-c291-51c7-a13c-1c8f6b061e80",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d5c50c-c9ff-5d56-8cde-2989eba2de5c",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b1e543-e553-5bc9-835a-0c18886fddd3",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff5cc44-0e02-5265-afb9-623b58eb0369",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5cf916c-61b5-5f96-b14a-190355b69f69",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24244d91-8607-59a7-901a-09ff365556b7",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f81e33-37d8-5744-9ff8-e4daa19b24e0",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5250f1db-c4f0-5ed6-abd8-a3aaeba66464",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11958c0d-6a88-5773-bf58-a7b1a4479cc6",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.sts:cxf-services-sts."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts@3.4.5-tuxcare.1"
    }
  ]
}