{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af036ed6-5e6d-54d6-8487-4dcc2c59ecdf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-service-description-swagger",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dd2b2199-fae6-5b3e-8d2b-f5d7083c368d",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602ce650-5f4e-5419-817e-678840b35f83",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5230689e-3dde-5f7f-8038-8f2b1007f6f4",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e571af-9895-5ad1-a477-0dd00529413e",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c5ad95-5234-5bde-b198-adf62cdb4254",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a11ed122-4d26-5bcf-97ac-2b7e28fbcfbe",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fdc3384-793d-59da-880e-37636974e085",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be18f84-08c8-5998-8aad-2bbd569c34a4",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:858264bd-b1bc-5332-9938-57dac7957fb8",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78a1142f-51db-5eb8-ac42-122d71d6e64d",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff9b2e4c-96e5-514a-8a6f-749cac9025d6",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:189a2399-ffbb-51c3-8175-884a0f5f1d52",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:180d3b65-c019-57c9-a577-75af0aad3c8c",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93c06288-1c10-5f8b-832e-2b9b8409a281",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13adfbcf-41bc-5715-abba-ba87175bca59",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a493b0c-332b-57b6-98a0-ba3b91451e1d",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea135781-c8e5-5abb-8f44-d02b2909f12b",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d2fce3e-f674-56fc-84ed-15c8cefbf208",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ae0ac3-03de-5df9-a3d2-fac146f86579",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99e9f342-3331-5e98-ac1c-5a14cd3fb983",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5192f41f-04a2-59e0-888c-c736687bbfb9",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7bd064f-f388-5a37-a061-af521bcce5af",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description-swagger."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-swagger@3.4.5-tuxcare.1"
    }
  ]
}