{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5b9d0334-9d3e-53d3-80a0-0688cd6da632",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-transports-http-netty-client",
      "version": "3.5.9-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e629bb26-aea8-5294-9218-faad761bd189",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9fd277-4047-5251-8935-41fbfc2d4acb",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f058f81c-10d8-5f31-a905-2a3310efd396",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b0b59ac-1995-5517-a1a2-ad2d12e264d0",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4129fcbd-ff1b-5378-9a55-df0d7932ee0b",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1347624-ad25-5086-867f-45c6c210bd65",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0258e29-2eff-5713-81c0-30e89613578d",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb9333a7-b54e-51fa-9b18-e63d5c01671f",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e90663f-74ff-562a-b58c-dfe40cad4ff5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c112836-94c3-5b62-b6da-8447fffa2da6",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ad9e1c-779b-50ac-9c2a-a3e728d32640",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e38884-ca69-500d-bbfb-6a34911b95d8",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e54c759f-c588-5d85-9ec8-24058ed1455f",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a32db1c-850b-5236-8de0-6093f38d39d2",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab82e99b-6d89-5c61-8380-d115ac96a52f",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae6a304-580a-5a0e-8e4c-6eedf0298def",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6442543c-71f5-5310-b173-fa282e842ebb",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-client 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2d59046-d872-5737-91c8-01a2992e679d",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75dffd4-915f-55cf-b7e4-b598dcdff39d",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4494baa-34ca-5337-9173-feb7b4f1da82",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0baae5a-698f-5b02-8f1a-e8e8f4e74825",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ae86192-a6d9-585b-81d3-f1e9a4b732da",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599eea53-a55b-598c-a28b-61aef4f4cd67",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aa04b3b-e28b-55dd-a5b6-a69d6bbf2fc8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293e87d6-551e-53eb-b538-aabd3c3f07e4",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab17db1-aea9-5473-8835-cb7e6fddb20e",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-client 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:561636ab-f77d-52a1-bb05-77d11ca988b8",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09448427-b90f-50e3-87c6-abe37ffdf2b8",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b059df5a-e2a2-50df-acfa-0fe4466c6742",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1338d0b2-6022-59b7-ab1c-e24f78e6fc9e",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-client 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db396945-abfd-5d99-9d65-41df510944f2",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f2928ac-b0b5-5aa6-a159-a2a32d03288f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:791caae8-a44c-53f6-a40a-4d57adda666c",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:439b2423-fcc7-586a-99b7-9b1366025e18",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-rt-transports-http-netty-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-client@3.5.9-tuxcare.4"
    }
  ]
}