{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ce33a2cf-ff8b-5939-a52c-2abf30419eda",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-systests-jaxrs",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fd07f281-bd48-5f8c-b585-fefac5788f76",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0eb3081-279b-55ef-801d-28be819b41d4",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9aeb2c6-15da-5258-841b-e1fce2a5e88f",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f9f009-a610-504d-8e5f-399f11233d71",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0d85659-e95b-5ea1-85c8-53a503ba6961",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3efa2d88-c396-5e2f-b0e8-c7e0c076f55f",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd6e8034-eb6b-5658-9c7a-70d8df82921a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e51ebdb2-8ae2-59f2-95df-46de9d72d777",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a78bf9c-6f68-5e1f-892d-61e24ded9fb2",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e562b293-f5e5-56fa-9439-a44cceb26117",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b69d7537-e9ff-5338-a9e3-bd59fa7ef7a0",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a1139f-f93f-5206-a642-483b0ce2b639",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53536be1-b3f0-5c80-85dd-a20bca377efc",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1d32c22-67f5-58fe-805b-3d73383e9d32",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f90bb80-9097-5e5a-8def-d0f89664651c",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea8e5221-64ea-5ddf-a27f-35ff7f144827",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a086cd6b-fb4d-5ed2-8b98-4223f3bc1655",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ada407a-1694-5391-8548-3456a78c10da",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6020641-4238-50f7-b1b3-910b50acef04",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7300e57-02dc-544d-a254-177deb16d007",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a47281-66b9-5c51-9516-9276822edfaa",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0973b487-f83a-5624-ab3d-1d3a1a7b11fb",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.4.5-tuxcare.1"
    }
  ]
}