{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ee87d729-37ab-595c-ae7e-08d909d10412",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-security",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d8123675-10cf-5914-bcdc-25d713edea5d",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf05b7f4-22e7-5a90-bf59-7c78550e2c58",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42bd8464-96a0-55eb-bf7e-248f1fd3f714",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bccb3c34-13b2-5912-9286-51287ba7a8cd",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb40e1d-04f6-505e-a6f5-d07a3eb2acb9",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f278aeb5-bfd8-5c7b-8b2b-334d5dac189b",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc1a311-90d1-50a5-b8fc-e11935980b7a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a295064b-2e35-575a-9c05-a4501dce0827",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e54e6137-049e-5dfe-a725-c22c6df192e3",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1331ea2f-3bbf-59e3-b2a1-31e870887716",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d60258d-b67b-5b9e-85cb-1bd822b37576",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1456268f-3463-534c-85d8-73aaaad40344",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:814f2656-11d9-5c8c-8f8b-cf3477ac1809",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d405743-d43e-531a-9e77-eed4ff52fbb3",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6cc4e0e-a648-5eef-b21f-3be770a37d23",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adcfb459-c96c-5f5f-9bf2-06142e176354",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14f1d09a-79b9-5cca-8ed8-425b2cf88008",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88bca120-a579-5e29-8ae9-2d6e1d4b2d42",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:820cbf13-2775-58ca-bd9e-1d69944316f6",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9f3576c-4df4-50eb-8c49-5887d505c101",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc8e233-d084-5cc2-839d-f11e13d3449a",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04dd520a-060d-5117-9ce0-950d077b0186",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.4.5-tuxcare.1"
    }
  ]
}