{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7b3ab585-5d36-5433-ba15-8681f1b951fc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-transports-http-hc5",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d218ccb2-4df0-5e09-8a6f-262b303923b2",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20d23d9e-2528-5d54-bf0a-80adad1cc3ec",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2e82946-fc5b-551c-9246-a514eb4110b0",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6411bf07-cce6-5533-a70d-a90ed03006d4",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d367a54f-c565-5139-b3e3-dba39e098940",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bd6ea88-19c7-5136-a7e6-71d2c38ced55",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4cce77-ff94-5695-954a-0b1834f09520",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6736fb-548a-582a-81c5-09b3d8833023",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ef17d5-eebf-5fee-9391-ed21b8d5a51e",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:236a5b7f-58ae-56d2-82aa-f36bafa5cc76",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6596bd5d-c747-57a6-b064-c4f1e781480a",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15757d4-e570-58e7-b994-e3ba5fab73d9",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28247437-b35e-51b2-8381-639ca0b66441",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:710d9f34-6beb-5144-9b04-80bf78743ba4",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8af0aaf-0daa-5cfb-82d2-20c86d037de9",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e3467b9-2b63-5ad1-a396-9e367b9764fa",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8f711d-458b-5f03-a75b-2644cc0ba04b",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-transports-http-hc5 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31bc6ddf-c266-5adc-8306-08037b406bd8",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d6ade3-8fe9-5920-ab36-889321cefe04",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e51ca6-78ed-5a67-aca1-3f5a1c35f511",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4d19a5-cba2-5db5-b467-0397d87fd84d",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da28f697-dc21-5d96-a96d-c9a86dfd04a9",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bb42c68-5504-50c0-9693-c0faef7a45c0",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f9cd73-22e6-5246-bcc2-ad2fb40eae30",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cbe4573-8524-5809-ab7f-b757a05b4989",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3021250f-7c0b-50fa-99d9-d690aba405a6",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-transports-http-hc5 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d40db6b-9cff-5b35-9485-d12a8ce2d557",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4f1473c-3860-5d5b-ba95-d7be3415c163",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de64f8c0-ee71-5bd8-98d3-37f597f74574",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce678c0e-cc82-5260-9f29-8fb2fef60851",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-transports-http-hc5 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21cb1f6f-6b83-5397-9ca2-44bb6d8d0f8d",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:069261a7-5c4c-5338-9f1c-652b56d698c5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea19efd-e099-550a-bcb5-6a093459b153",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7191ba9-46c6-5b23-a993-fe643de6a939",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-hc5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-hc5@3.5.9.tuxcare.1"
    }
  ]
}