{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8746a8d6-0a8c-5f06-928e-a33fb136c8ea",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-cdi",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b09fcf52-4a85-53b6-ada6-3543237a3d41",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:504c58b8-8a7b-5999-a617-3aa575ffea48",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41a1e171-62fd-5e93-ab5f-6c1a3f0b58d6",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e687e1-4e5d-5afe-a661-9dfc2c9147ac",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23403322-b73e-50e6-873d-dfe75b4b0008",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a10013-0693-58a5-afe1-54dbb2904c7e",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f4e718-8675-5adf-99a4-0c1258633a42",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2d60fdc-0c01-5d1e-a4ac-2d121e55531b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aa8bdf9-81d3-5b05-b315-57afbb234575",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fc2673f-0732-5b29-b1e8-e771ab96e73f",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78cf81eb-5a2a-5a70-ad17-45b4f208ad3e",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c764bd-cdc7-5a0d-bdd3-bf20771aa10b",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd77bc8f-2e85-5dcf-96e9-41144c433cd7",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d90fc6-4d17-5fcc-8ef2-5668d7596893",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e06ee56e-0dab-5fd9-82ba-ea9f0566c93d",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fae78beb-d8a2-54c8-8d52-3cd2cdf7e7d5",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38964d0c-57b2-5dbc-a1c5-79dbcc18c159",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33e430b2-5c3e-54f3-bea2-a691e19e1d41",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87569674-b780-5d05-8506-8d2ee54d796f",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4422b46-ae14-5e18-ab74-d54caa41562c",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:185e351a-adf6-51df-a6c3-9d8af7ea75d3",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:360d4554-009e-5c0b-8cc7-4a0bb6325463",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-integration-cdi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-cdi@3.4.5-tuxcare.1"
    }
  ]
}