{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e853b1b0-9843-5deb-8f3b-f1c08a326eae",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-security-saml",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:18712bc9-0973-5f21-beda-27c11387f74c",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0b71316-8650-531c-b12f-0dc55a8cf71a",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:588f6758-13b9-58b3-b7ac-c349fabb76e1",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba948a3a-55a6-54d0-b9f1-261e68ec5267",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4a9e33-ba26-5906-8802-184f8c07e9bb",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b931e773-b7d4-521c-9914-57542687ba22",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f45a46-2365-533b-88e6-56d59d61293a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:837fd6cd-411f-5c18-9c11-84e850a07ca8",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3efe4133-a0ec-5ce6-aa55-a16495efa308",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c19ca56a-bd0f-50a8-baf6-0ce9da5dedc9",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e4bc4fc-62db-56d8-b9d8-d2d09cf01a3b",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c42809e2-7495-5af3-b925-369e4eee673d",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c669865a-0100-5fcb-a549-5204b492c187",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bf8faa8-aeb7-5bdd-bf0e-3b3321a40f23",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afad6570-990c-5cd4-8f56-00964ffc4ad3",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c2e3e2-769b-5256-9d68-c2d0f10f7ae8",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cbc1e44-3c05-59bf-bb8a-4c30bc6efb95",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d720a05-4464-5eb8-b956-c4bd7aafd7eb",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c05d27-2959-5f42-994e-85c0ee2421b3",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0901351-2c7d-5d8e-94e2-967823795248",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:152aa642-a828-5800-bbfe-06688bdfd190",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe4d1c9-89be-50f0-8afc-b5c3821997ae",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.4.5-tuxcare.1"
    }
  ]
}