{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bf8d12e8-a8d2-5639-910d-bb30439b02a1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-testutils",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8201728e-60b0-5391-b415-5f5c966c1dcb",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2005-4838 does not affect version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils. Patches already applied: f3932a9ab64689e354e9c36da95f001049fde13d (already in target via 6a984d1184f 'Adding a test for the service listing + private endpoints'); 576b9b55ff80b118bc16c33df755ae518ba5f13e (already in target via 1cf50e500c9 'Fixing issue with multiple forward slashes in services listing stylesheetPath')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981a3d0b-0fea-53ef-908c-872b0edaf936",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c897712-5773-5a1d-bf63-45d1b6e167bb",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2007-1358 does not affect version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa8b8855-581b-53fc-9409-0d2e7deb8120",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78623718-e277-513f-8f42-fe6cd86c1f70",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01d3619b-4c85-5fde-b2f5-4e9d1ecc8596",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75ca6371-7831-5a23-b571-7fca6065a32e",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2010-1151 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2. false_positive \u2014 CVE-2010-1151 concerns mod_auth_shadow module for Apache HTTP Server, but this repository is Apache CXF (a Java web services framework). This is a wrong-project match - the affected component is completely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8fecde-07e6-554d-b668-3458aa9e1875",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:264fa102-a8f2-5303-9a5c-6700801ec7f2",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74e3cbb3-fa5f-5820-8240-ef7c7397a88a",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acf0e408-6b2f-54a9-8514-e11240fb017c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17b8a834-1041-5949-a2e1-1446391bf230",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4bc9b28-cad0-5973-9e13-67ff0941bb87",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2013-6357 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2. false_positive \u2014 CVE-2013-6357 is a wrong-project match. This repository is Apache CXF, a web services framework. The CVE concerns the Manager application in Apache Tomcat 5.5.25 and earlier, which is a completely different Apache project. The Tomcat Manager application and its vulnerable endpoints are not present in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f82c16-27c9-5100-bc2f-a816c64e6464",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fdcad1-3862-5e21-9bf3-7b8b6b560ef5",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5b975f-9c55-5e22-88a3-145578aa8192",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af53714-2931-5c83-990d-4b588f54fc98",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d54531c9-50bf-5657-93dd-e7df41324b04",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6db2ca4-ed9c-5927-9cef-9c13be1255bf",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-8735 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2. tomcat cve"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4cd10e3-b2ea-5d94-964a-6313dc7abd8a",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-8750 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d10653da-47d2-50a8-82f0-e53c76879f50",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:217ab515-3b8c-5c8c-8d9f-7b6c2edd7a68",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7222ed1a-dda4-5e5f-bd3b-480d69335825",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61f8522a-67a0-5d3f-b7a5-0ab75f58a3a6",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0226 does not affect version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils. Version 3.5.9 is not vulnerable. Summary: The target Apache CXF repository (version 3.5.9) is NOT VULNERABLE. The path traversal vulnerability in filename handling was fixed in CXF 3.3.4 (September 2019) via FileUtils.stripPath() sanitization. The current version includes this fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37a74bd5-e0e4-56fb-a05d-6bd4a1461a6c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-11980 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2. CVE-2020-11980 is an Apache Karaf vulnerability (JMX MLet getMBeansFromURL SSRF / MBean registry pollution, affected <=4.2.8, fixed 4.2.9), not Apache CXF. Mis-attributed to this cxf project version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45dc7d98-9e45-5d86-a91e-cf3f672e81b9",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7db63cf3-6bf5-545d-ba8e-7e96b683deff",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-41766 does not affect version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils. Patches already applied: 8d26f00b092981e1b2dabd0bbf373294b04a25d2 (already in target via bfd0de3e278 'fix for CVE-2025-48913. JAVAELSCVE-15580')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88e41722-6910-52ad-9bd2-c023743cff39",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2. false_positive \u2014 This CVE concerns Apache Karaf, but the target repository is Apache CXF - a different Apache project. No Karaf component source code (obr:* commands or karaf-maven-plugin) exists in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c607fcee-5785-5b78-abba-f86dc1c79116",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:408e9b16-166d-588e-831d-6fe243f80caa",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-testutils 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2614c0fc-c4cc-5cbd-a3f9-fe437dc0872a",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e0c2290-4935-5b29-a352-628d1c77ab41",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:846b49f2-16ae-5fb4-b52b-0651b77a4fee",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88f30ed-7634-5bb4-88ee-b8679bc9a20e",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86d1376a-2f91-5684-9b33-58754112f29c",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79d6cc82-220b-5311-b864-922799b6224d",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4ace30d-7542-55dd-8f04-42c50773b53f",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25165919-9ee6-5692-bcc4-89e73f8443c5",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613643da-4eea-5c80-b105-a25c7b8b2f2f",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4642d9e9-78c7-5a80-9704-3dc94985af36",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ce8bd09-603e-5318-b406-f5af7da88de9",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f98ae3-c6fc-5a92-b208-589ee9c62240",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd04e124-f143-56d0-9f26-700b63fca7e1",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4ef795-9101-555f-9876-d4b96839b484",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d71538-52f2-5eca-bfa1-c8ebbcdb46de",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca947bcf-596f-565f-a2d0-642156244621",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db17091a-c779-5740-95a0-7a825172d72a",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-testutils."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-testutils@3.5.9-tuxcare.2"
    }
  ]
}