{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5e39ccc7-c452-5526-967b-8f4a4cfb9079",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-security-jose-parent",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2b70f3d9-dba2-5df6-a108-ad63ed8f23d3",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca79f4a9-2866-55a2-a351-5a620552d441",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44d23df-4969-5997-943e-4ffe8ae239dd",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58c7bed-c461-5447-99db-379529abc8f8",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6712d33-106e-56d8-aa33-d8a16d65185c",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1213a856-37cd-553c-af90-00266b1f6aa6",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da7b3371-880e-5b5f-8f77-1fb53f817852",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe722e6e-cd99-5de6-840c-30b5aec803f1",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91c7ed15-54f7-5142-9521-6f3a95addfbd",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c8122a8-38c2-5614-be77-d1de7a62ad6d",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38e10e3e-c5cf-581c-86c1-be14ea696a10",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dec039a0-b1f1-51f0-a0e0-4c0e5255ae97",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82cb5523-d668-59dc-ac50-683d079d4f52",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e353bc3-2d6e-55a4-a246-c8ec1864c3e4",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a5d926f-5670-5d2c-8f2f-a0a64fcdd5f1",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:808938d3-1d84-5bcf-9ef8-5dfce7e42ada",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad58205-f7fa-529f-85d4-a8d963ea990d",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-rs-security-jose-parent 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5377268-6cd7-58bf-b2a4-1f07812b9011",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acf81f46-980a-5a36-81af-d7785d3f1c78",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ba18abf-ecab-52da-a78e-c4c839e8a6c2",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d00cc0b-06c5-5381-b379-dfa7dd1b55d1",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd086cf7-cdad-519a-915b-2589738d36bb",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:785abfcf-8cfa-5cdf-8455-ffc866b9e4b3",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0772710-63e3-5301-ba0c-9691da2dab84",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca73136-1f1e-50bb-bf80-10f2dfcd3576",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f03489b-2dea-5f35-8eb7-9e1691701815",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-security-jose-parent 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9f6c51e-d3e7-5344-a895-f0c2d315b129",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639b5749-b681-5e27-9509-e8519acb8fbe",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a410c6-72c5-5e27-b70a-7e7175215483",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ec0823b-25fb-5871-bcc0-462494525af7",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-security-jose-parent 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1be9437f-54af-5d4d-a4e6-5d29a42da019",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9a0506e-5a9a-52f4-b562-9635faad747f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c910e6e-33ed-5302-b428-a32b91f27fe7",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:291be389-94f0-52d3-930b-3575e3a36b5d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-rs-security-jose-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose-parent@3.5.9-tuxcare.3"
    }
  ]
}