{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:40f5c7c7-dfe0-58a1-966f-83529655219d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-systests-spring-boot",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dd90de4c-395d-5688-8c33-bf424c5cb725",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea0fc51e-6eda-5cab-9db9-4bfb4eef4ab3",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6050e9d-1848-5456-964a-1632e3681b17",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:017a00d5-f197-5f2c-9273-5f3b4abd36b8",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:126fb248-0ed7-54d1-b2e8-42ceae2b58a6",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1229160-f039-5264-b32e-c4cc13df46f1",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a4934b-cb90-595f-9259-14ff2b7eeae7",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e26fcf96-3dc4-5459-b4e6-6c1e9e60476b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da2e71f-faae-5311-ab3c-e8c724cd1b99",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e875298e-a69b-5541-a48f-2bf63812c2ff",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87abbe85-7b27-55ce-a939-f131f7daf133",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e681a13-a74c-5a4e-a1c7-590ec7f41dc4",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb829e7b-3baa-5d1f-ba5f-4331231ff68a",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78aeea8b-a4d1-57c2-bc27-caf755912833",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308a826c-c59d-5e76-8eae-4cdafc670105",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d702b873-61a6-5220-8a79-83ed3cf481b3",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9efbc7a3-4f33-5bd0-b2c5-6a7bee7a6b83",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:728d17a6-8dfb-58aa-9778-28f74ab04d6d",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f7fd1b0-f82d-562e-8604-8a311d9f0029",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:619d8971-51ba-507b-b227-5bd07c9d48fb",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e38862cc-edcd-5a5c-a1b3-f7b71f703476",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab400b7a-63b5-55d9-b04e-bdfcac44e407",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf.systests:cxf-systests-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-spring-boot@3.4.5-tuxcare.1"
    }
  ]
}