{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3620fd1e-ff6f-5655-b9eb-8d8da7dac577",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-java2swagger-plugin",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d5d602b9-792a-554a-b024-3a853482155f",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b734e2e-5fc1-5e0d-ab44-58b2ea021310",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4988ec9d-1fa6-5d52-83eb-e7817c19dc45",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899d1651-fe42-504d-b713-1446a4110b68",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83c69a71-20fd-52ed-8b1c-e112437479c7",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4c7044-c4f2-58ed-9f2c-d6fcb85af70f",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b776f1-73a1-5cae-b4e3-30d9d0866cda",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a9f1048-da1b-5c11-ab42-113af1b5acef",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b520c7df-f930-5faf-8dce-4f3cbc5d64d3",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c28acf-4965-54cb-befb-67dad925ebc4",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e40de0f1-d201-513c-b562-ee83dbe50a34",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede19c78-e8b5-560a-b8c2-0b70be7eed40",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7247fd37-4d37-5a7a-97ea-583891da3a86",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d975de56-d12a-583f-999a-8680ebf024ea",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e4dd861-6a7e-560b-af95-bdb1e812cae7",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ff9d9a-5181-547e-b904-efb42638e1de",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af5069e7-bc66-51a8-89ea-dca10152e1e2",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52270f40-448e-580c-a062-60dbc2b1ff0c",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d48bbc-d68d-54f4-aa31-67d0af91d583",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:126fc4c9-bdbf-536c-92fb-29f135b730e5",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7e69a11-e338-539b-afd5-2466f1ce763b",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80532c80-5870-57a1-9bfc-7d235a0eb4ad",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-java2swagger-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-java2swagger-plugin@3.4.5-tuxcare.1"
    }
  ]
}