{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d08a186c-08ae-5ca4-b53c-7938f64f16d8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-spring-boot-autoconfigure",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1fded30e-1eb4-5a7f-bcf3-4e33b0eb935b",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63a2cef3-3725-5d31-8e0d-0f8d0677e745",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f3b7070-54ea-56ba-9f29-4aa16a14eae2",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16f55296-1812-5139-8a89-678f0078960c",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7286c6a-e53f-5111-853b-456423310a3b",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdb986f4-0369-5d90-b47a-fc7d273b86b4",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27c7ca9-40bd-5b46-9e93-ad8a20a13d61",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21400721-3898-556f-842d-0328e331451a",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:846f00e2-96d5-53d4-9351-49fec85ee607",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c48f73c7-3bd5-57c9-a5ac-19f2f7416e66",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f7149a3-748c-5abd-b961-37aec9934832",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9ff5f94-227b-5e3b-81f5-0281eec38c0c",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d06f037b-d643-5801-969c-10a1a6b6d152",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7239e85-74ab-572b-9119-472174d44018",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0623db77-318b-5cdf-8e27-846e94ff9167",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4346ce1-dc55-54d4-b24f-45fba6d578ec",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a90fb1b-eee8-567b-b206-7856f99e9325",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca3ec40-c3c9-59f0-9eb2-a08ad5604079",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43049586-93ba-5129-ac6a-f26f7c91d983",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00bad83-c3d7-5857-84b3-28e6169fe45e",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4cc9ba1-4748-5e10-b254-86e2a3e2e188",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50d8bff7-01bc-56cc-9467-d058b3123d79",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.4.5-tuxcare.1"
    }
  ]
}