{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1f865b3c-e27b-5fe0-9440-e08f09c77b17",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-distribution-manifest",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fc6cb3d4-7970-5ce7-affa-89eff88dc282",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a8ae2c-7c21-5fbd-956d-adb298ff698d",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c339d2-bc51-5748-a094-363a9a17c432",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11934067-3871-5fca-805d-cf1a0940df11",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d27528e1-b671-5fdd-a406-f384b1ed530c",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d3f8be-5eb3-53ce-855a-bcdbb5ce0d12",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0eeec96-ceee-5c9e-b627-ea205f84ee77",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da12b660-0799-5390-8138-38da7ba82157",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18cf104c-7b4a-5185-8c1a-bbcd39a1beaf",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27b3c7e5-77cc-5eeb-8d25-79a1751d75cd",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fdd47e3-ee2f-5332-9dd9-beeb1152ae53",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21ddbe5e-7638-5000-8684-b5276acf238d",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5a4b640-929d-501c-9713-21fa7c435086",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eed754d-b622-5307-99a6-6b91832b6fe4",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f4da8c-c9b7-5ecb-854a-2db6cb0968b0",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52757300-22de-536e-9898-13e0a7080304",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac82ff1-0f06-5c19-868f-d9457425809b",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b4ed7eb-ef65-503e-87f3-cd1b196e0ca4",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7fcdb6-dc0e-5629-a4c2-8b1ec7a8ae54",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca33b17a-2e6b-5afb-9617-52a3a5bacb8e",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab468e29-3503-5e03-821b-b4c6347fb786",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c32bdef8-fc65-5c75-aafc-5fd44246036a",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.4.5-tuxcare.1"
    }
  ]
}