{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:acd186df-a7d3-553b-8499-344cc4004a47",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-tools-corba",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:684e5a3b-e992-5929-b309-30137962ee26",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0398ecf7-0d77-5a0f-a5bd-916729d3a45a",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7214d410-4ac1-5224-96eb-e66b61df6545",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a6cb5e-8c5e-5bc0-96f4-9fd66c0af7ed",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:407f3682-42dd-5252-8a9f-30268d09bca5",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d160e7b-ec63-580e-8368-63ffa5c78e67",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74345f1-2ce0-5eb2-91fd-057ffa2a149a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18e206b5-ca5c-5eca-b2bb-4d4d6466c6f0",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50682986-cd27-56c4-b28c-54dbdb75fd31",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c30297-55c2-5567-ae27-8e5846e685b2",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22fd798e-6d2a-5f3a-9fc3-aea78f6b2150",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a9c9e0-320c-53d3-9a80-bfb2bc4b59d0",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5779593d-0264-5107-862b-15c11c0c0079",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85f37f92-02aa-5500-bb8f-7c3e2d84c6a2",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1602ecd-eb35-568f-8967-2b68eec75d27",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4962edd4-c428-5faf-9b43-e03d7c43ef45",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab63d196-059e-5a62-9453-d31649921451",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c259084a-dcc8-5c30-bedf-9a7f36ef0f5a",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9330440-1b92-529c-80cc-ed9f4e7cb072",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec04806c-aa27-551e-9276-fbb03b68a60e",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ba37e9-ac0c-59d7-b2b1-a7981e677808",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d10f1331-54e1-58f1-b031-64c6057624fb",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-tools-corba."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-tools-corba@3.4.5-tuxcare.1"
    }
  ]
}