{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a9996db2-6282-55f7-b7e8-52daebdf8e9f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2",
      "type": "library",
      "group": "org.bouncycastle",
      "name": "bcpg-debug-jdk15to18",
      "version": "1.78.1-tuxcare.2",
      "purl": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4880f973-dfed-50f4-93d7-388dbc0c03b0",
      "id": "CVE-2024-34447",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-34447 does not affect version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18. Version 1.78.1 is not vulnerable. Summary: CVE-2024-34447 is NOT present in this Bouncy Castle 1.78.1 codebase. The vulnerability was fixed in commit c47f6444a on April 3, 2024, and this fix is present in the current version. The fix prevents hostname verification from being performed against DNS-resolved IP addresses by setting peerHost to null instead of an IP address when in client mode without trusting the name service. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca962bef-0e91-5a82-9c5e-f8824c0e9712",
      "id": "CVE-2025-14813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14813 affects version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f231c9b-9361-5d45-8f11-a2f5b10c0db6",
      "id": "CVE-2025-8916",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-8916 is fixed in version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae23e4b0-c20b-5680-82b0-a9965d165282",
      "id": "CVE-2026-0636",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0636 affects version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b75edf-5c7a-5517-bdf2-b4470fa70d8c",
      "id": "CVE-2026-3505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-3505 affects version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61502c4-3a48-5689-bbf2-f6cafcb015c7",
      "id": "CVE-2026-5588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5588 affects version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d55048e1-ae83-5a40-8cdf-0292c5abe708",
      "id": "CVE-2026-5598",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5598 affects version 1.78.1-tuxcare.2 of org.bouncycastle:bcpg-debug-jdk15to18."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.bouncycastle/bcpg-debug-jdk15to18@1.78.1-tuxcare.2"
    }
  ]
}