{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bcd29558-fee3-5167-b27e-f4dda171cbe4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-extension-reactor",
      "version": "3.5.11-tuxcare.6",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c072e000-fb8e-59d8-b346-ac08789f1b80",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14caa360-b9c8-5b84-aa66-93dbe8ac9cf0",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81030b8f-a731-54e9-86cb-cfeeb86d0e8b",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0761d8-3f40-5a16-9e22-3d1a9b9d53d1",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03f1938-687d-5533-b8a2-4a61e65c508c",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebdabe13-731a-5e31-a163-d1c23c256e81",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ff83e31-68de-51ed-838e-a13ffc4ce560",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:918dce0e-8a24-55c6-ae76-aedfac2774af",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28a874cf-4f71-520e-b147-2d2e46e5eaac",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70d39c1e-938d-5860-86a9-3011266e5fda",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e25f02c8-75ee-520b-a361-3e952f66c270",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f63016-84f6-5327-bd46-149374a09b2e",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3261b19-b0b8-5956-8401-b1ff86f7f2f6",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63cd89a7-7ae0-598e-be57-71ee45714e3c",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27f81dda-86f5-5995-b6d1-bea10fcaf689",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a25e26c2-c9d7-5f36-99c8-33e9613530b5",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f74a917-cb8e-5802-861c-d9ff016422e1",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d9e4e27-7c66-5628-9aba-70eb38dd398c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a8ed74-e0a5-5322-9c6a-53fb810060d8",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8c2ab2a-c52e-5ec5-9550-52349ea5bae4",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f90b1830-fe8d-5349-a12b-64e382285c1f",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c42c8f0a-4f3a-5f1b-b2d9-1e41bafc6062",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95c15e81-6189-5b76-9772-57a7c5c9e3c8",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:481288ba-6afa-51ea-a558-d1c2a2b842d8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d6f2769-7104-5902-b7ce-9a77ab42b762",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c5d60f-3f96-5105-bbb5-c6633bbbba2a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-extension-reactor 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a4babff-3eb7-5957-89dc-3c440ce90a1f",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54a04c2f-ead2-5ff4-8f18-62353ceb83db",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-rs-extension-reactor 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a135851f-470a-590d-b338-36fcc522da68",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:711d5f06-6c80-50cf-8002-627b400c862c",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-extension-reactor 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:198d0fb1-80e3-56bd-891c-7382d908c0ab",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8193a3d5-ad29-5d2a-9cc3-9800df151cab",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-extension-reactor."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactor@3.5.11-tuxcare.6"
    }
  ]
}