{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a4040119-237d-51fb-9e1a-a44721b83f0f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-bindings-soap",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5f22ff13-b776-529c-97c4-74e930155ceb",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af21e467-290f-5f19-898e-5b9c79230e43",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc683e9d-aa35-5f35-8e1c-32012823b0e9",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f18095d4-34c4-5a70-81db-1caa5bc1c860",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e8d1d10-c535-596c-ab2b-85675eb42220",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa139dc9-6c95-53a6-8774-ba97b2dfe48f",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89556b93-6339-575a-98a8-c8b1d6cccec7",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cde07e9-5af0-5652-8787-a251ac626743",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bba1509-c40f-570e-9548-ce6b171664a7",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff966b1-b95a-5be9-a83c-6c8da075fbc8",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cda98fb2-0fb9-5bf2-b618-3dff59359554",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43efa716-9ecb-56bd-b79c-695a001d2550",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c8c7a08-0b09-50ca-8b10-415ad4368619",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06315a1-e36b-5972-b50d-d56da715acfe",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8027a1a6-168d-5bb9-82da-ff490950ac47",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d50ae809-e09f-5162-b3bc-c4a1766c5e1a",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c432ef-2c90-5656-8a82-6261029712d9",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df95c2aa-0700-5edb-abca-db513f8dcb71",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27460493-bfce-5a00-b76b-80f2fabc7795",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e500ae2-9d4a-5758-a264-911d6458c8fd",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4af191a-ad96-5a43-baf8-645ab1508f9c",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc770263-9b67-5765-a7e8-dca2c2202c6a",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.4.5-tuxcare.1"
    }
  ]
}