{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:82afaf9d-66f3-5d28-8213-341f1d93c1bd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.services.wsn",
      "name": "cxf-services-wsn-api",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0978e4d2-5778-51d8-bb20-84fda73c478a",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f62213-fef3-579d-b0e6-57eab637ecef",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea208d0-9a5e-5013-96f2-7e731ee75f28",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8308ecb0-d052-579a-a346-8a4cf9467e0f",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e13da6-6604-5f4a-a894-be43c4a66e71",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad817cda-e93f-5b77-a97c-6f3b5fc1c032",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59e41970-8808-5198-a92b-bb77a83aad50",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:992efd50-07db-5ea5-b98e-50ac5557f9ff",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee2b1928-3838-5d33-85d6-da0b0b13044c",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7abb635-ae59-5cda-a83e-4f8761c452b3",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d618df-34cb-5e97-b6c2-5d2429f3f65d",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5946642-6bee-57f3-9155-fb9b3bcdb63b",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e67597-79b2-5bda-a66c-01b505803ffd",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a02a2d-e87d-5fca-bc33-ca87864751f1",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2171c986-84e2-5896-b7d1-9dc93bf8093b",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad2fa30-ef18-56da-beb1-e0510be5cb77",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51da4c3b-20e9-55e4-88b0-d3a30102f255",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e5e06ec-46bc-5b57-8535-6877e0aca531",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84c0bdd1-a5e4-5e9e-99fb-042d7a62c874",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88fd492a-11be-5471-8a7e-0734a004a049",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07628c06-6f41-5e41-9450-70b79c67a847",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6eed115-dff3-5729-8cb0-95147987b775",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.wsn:cxf-services-wsn-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-api@3.4.5-tuxcare.1"
    }
  ]
}