{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c714b6c3-b111-517e-aff3-67621b2eeeb2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-testutils",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b33cf914-7fe3-53ac-9183-a2bee7a18b2d",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2005-4838 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2005-4838 concerns XSS vulnerabilities in Jakarta Tomcat's example web applications (examples/jsp2/ directory). This repository is Apache CXF, a completely different Apache project. The affected Tomcat example applications are not present in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3469a431-7ecd-535e-87b5-2aef1ed8bdf7",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2006-7196 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2006-7196 concerns Apache Tomcat's calendar example application (cal2.jsp), but this repository is Apache CXF, a completely different Apache project. This is a wrong-project match - the affected component is not present in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd321ac-7caa-5e25-8b3c-1ff18a0c8d27",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-1358 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2007-1358 concerns Apache Tomcat 4.x, but this repository is Apache CXF (a web services framework). The CVE's affected product code is not present in this repository - Tomcat appears only as a test-scoped dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d6408c8-6d8e-597a-9103-887cb2a4ddf7",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2007-2449 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2007-2449 concerns Apache Tomcat's examples web application (specifically JSP files like snoop.jsp). The target repository is Apache CXF (org.apache.cxf), a different Apache project. Exhaustive containment search found no Tomcat examples web application - neither as the project itself, nor vendored/bundled, nor as a runtime dependency. Tomcat appears only as a test dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a43abb4b-d8c4-569a-af6b-30e6cb01573f",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2008-0128 does not affect version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils. not_affected \u2014 CVE-2008-0128 targets Apache Tomcat's SingleSignOn Valve and JSESSIONIDSSO cookie. The target repository is Apache CXF (web services framework), which does not contain Tomcat's authentication infrastructure or SSO functionality."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb35ff7c-5e1c-5cdb-b510-38de5b66a25f",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:725dd34c-f29f-5b37-9663-69d8f44dd7dd",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2010-1151 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2010-1151 is a wrong-project match. The CVE concerns mod_auth_shadow for Apache HTTP Server (a C-based authentication module), not Apache CXF (a Java web services framework). No mod_auth_shadow code, dependencies, or related authentication patterns exist in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a007b1-d81a-5df4-9693-cff7a5ac1ee6",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfdc0d24-aa37-5f7a-ae19-3d7b762a445c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f8b6e8-cab2-5490-bccb-aefaaa9bba25",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd60b3bf-4b6f-5c50-b4f3-3d59561578d1",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2baa92d-2c0f-5fb6-a9d7-bc7d5e2dd6d2",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4725f411-1ff7-56d6-b4db-6fbf65a5f7bb",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2013-6357 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2013-6357 is a false positive match for this repository. The CVE concerns a CSRF vulnerability in Apache Tomcat's Manager web application (versions 5.5.25 and earlier), but this repository is Apache CXF version 3.5.11, a completely different Apache project. Apache CXF is a web services framework for building SOAP/REST services, not a servlet container or application server. The affected com..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a137ea-4f0c-55ff-ace9-333d0b1b7395",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95fb67da-c7a7-54b6-9f86-b1f35e1babaf",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f1e9a6-f1f6-529b-96a6-efd746d4c929",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bba3045-ee46-5483-b0f8-c36563a1482f",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32788856-9d68-5ccf-812d-2598dfc256ec",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1334c247-db6a-5c12-a2da-aa0cacd99560",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-8735 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2016-8735 is a wrong-project match. This CVE concerns Apache Tomcat's JmxRemoteLifecycleListener server component, but the target repository is Apache CXF (a web services framework). The affected Tomcat component does not exist in the CXF codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d16f8552-f7f6-5a8f-9b22-2c81619a9955",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-8750 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2016-8750 concerns Apache Karaf's LDAPLoginModule, but this repository is Apache CXF version 3.5.11-tuxcare.7. The affected component (Karaf's LDAPLoginModule) does not exist in this codebase. Karaf is only referenced as an external deployment platform."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb6446c-65d0-5021-911c-181bbb23eebb",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fce1c876-e6cb-5185-b26c-71aebf644892",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e14da491-1eca-50b3-9375-0ba2bd2c5e52",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05449b9-e240-5f2b-9086-c66888efddd9",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0226 does not affect version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils. already_fixed \u2014 CVE-2019-0226 path traversal vulnerability in Apache CXF attachment filename handling is already fixed on the main branch. The fix (CXF-8101, commit 72574910b2) was merged in September 2019 and adds FileUtils.stripPath() to sanitize Content-Disposition filenames by removing directory path components before use."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b13f19ff-77f2-58b7-86d8-7d1e2ec381c2",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-11980 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2020-11980 is a wrong-project match. The CVE affects Apache Karaf's JMX management system, but this repository is Apache CXF. CXF does not contain Karaf's vulnerable JMX management code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f0e13e-f5dd-5744-948b-37a06415d5bf",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9932ab65-91e9-5185-9c52-947a09473746",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41766 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7. false_positive \u2014 CVE-2021-41766 concerns Apache Karaf's JMX implementation, not Apache CXF. The affected component (Karaf's JMX management module) is completely absent from the CXF repository. While CXF can be deployed on Karaf and provides Karaf shell commands, it does not contain or depend on Karaf's vulnerable JMX server code."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a6b71f-7e0b-5ed8-92e5-5291070a1053",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e6c7118-4afe-56a5-9466-edfd39b948a5",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64f8fe73-b6c9-57c1-ab8a-4f51803688a3",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-testutils 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a90323a1-e380-5d7c-acaf-249747191814",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adfb8877-ffc7-56f5-88ec-73fe0ae26af2",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1640791b-c3e3-5e67-b95b-7cc216336944",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9336f42-8d0b-520b-8a48-4ef03c524aeb",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6cafd8-8306-52ba-a5c4-d004324f1c75",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05303763-cfc2-514a-850e-6b61f71d4a5e",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbfe7727-421e-5530-b765-6c7bd847bf56",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0044daee-b0ec-5267-a1f3-61c26e4450c5",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:178a8ce3-d18d-5a58-8e5d-e2c6ac44dee0",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c9c1de2-71f7-545b-b17e-b44d8486b871",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:897f2b46-e6e6-592a-b180-674c6c565794",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c43f8b-99ff-50a8-ba9f-5a8f3deaf161",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9f4a977-22d2-538a-b5b0-947fee607927",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a109858-63f6-5d5a-8eed-b0fc40f1575a",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85cc9067-535b-50ba-8eec-62b328fb8a13",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50645 does not affect version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-testutils. already_fixed \u2014 Apache CXF version 3.5.11 already contains the fix for CVE-2026-50645. The vulnerability describes unlimited attachment headers during deserialization leading to resource exhaustion. The target repository has commit 6c3990144b (dated 2019-09-03) that restricts the number of message attachments to a default maximum of 50, which is present in the current HEAD (37beba7d7b). While the CVE mentions ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.11-tuxcare.7"
    }
  ]
}