{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c0a7225c-6c58-510f-870b-bbe1c0e6480d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-servlet-compatible",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c8f983fa-aecb-55e0-833a-cec21a4a3978",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ee203c-aa24-5913-9854-80100de38421",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5086409-3d0d-5f7d-87fc-78e51ae0784a",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86294a2f-aeb0-5b12-8a0a-cd67180b1f1c",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2216330c-30a0-551a-ac80-d30ab552515e",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8940e7d-667c-5c3b-b7c8-c0338c1d175f",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f75dbdb3-0202-5965-b3ba-85421dfebec1",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c69bc4f9-d998-55d0-a82b-8b0fcf98f818",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05cebea0-0552-5db7-91ae-da61510f9d69",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70abdb5e-867f-58d3-ae0c-d76b12b3c4e6",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88f952a3-ecb4-5135-949c-adb9a415ef5f",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e193249-b76a-5b87-b944-855f230d5e34",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6dd6d07-1129-5f51-8b4b-d63f53d28152",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:636b8594-c34c-5c0e-9147-5b1ffb152c8b",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1699c4d1-dadb-554b-8b15-27575e373cfc",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd006c21-7c21-5151-a958-bb4c556c0dba",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b30a25-75a2-58fd-a19c-75c8796c8a79",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b319b94d-e420-5924-901d-c1ce7c8a846f",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85db3147-923a-5b0f-b0db-b95d2a0ac141",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ab00def-6658-5cf7-aead-baecf7fb7b4c",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b33e44-d274-53af-949c-2b87544d7360",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5e6d85d-973e-5e92-a221-c5434e8b36a5",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.4.5-tuxcare.1"
    }
  ]
}