{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2ce3780c-6e59-527d-b416-63700b688efb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-ws-eventing",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e68eb4eb-fe90-5732-9091-ded78426bded",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfa144c2-c006-5ef9-be9d-8a163ae80898",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecb49e1b-aead-5cc9-ad48-a323747c2e7a",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a10db6-9f38-5811-b74b-9fa159461fa0",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2881390c-5f6e-5088-aa1a-8d58a20a6d46",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a0d39da-9a1d-5064-b63b-7d3e02331f0f",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdf80c5b-da6e-54a4-a5e1-6296c1b5ec48",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5081d2af-919f-5c9c-87e3-6976bfd4ee6f",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dab8250-606c-53bd-8d61-7b1f1e0bc7ac",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe56cad5-00db-5e83-baaf-4666cbf2ccd3",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48dc9bcd-8796-5ffd-b537-31df8c1fa12d",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88fa1a17-1736-5584-a854-322cc3cd6407",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89434228-0ba7-50a7-9f45-70b3853e4af0",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e641a43-9668-5b29-892e-9fb77bbca937",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e13273-3e62-5596-abad-4b77aa8972bc",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34b42f9-fef3-5852-b826-556ae8712802",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab1f3b4-60d2-5774-b12e-c6c60b9a9fdf",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:809214a1-d307-50e3-a45a-4566a168524a",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c55de7-6563-5918-ab94-bdd5e9f6cd73",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eba9c3c0-ab2f-5897-ba18-1c285bd1d0e8",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61dd4321-9e11-50a7-bfe3-b16eca545122",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab43cc3-7a20-5453-8dee-1b549b24a493",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-rt-ws-eventing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-eventing@3.4.5-tuxcare.1"
    }
  ]
}