{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0839a0f1-ebc7-59ea-86fe-da6ed5e0bac7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-transports-http-netty-server",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1a0b342a-96f4-5b1b-ad27-bc8e51f9c5f8",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2bce63c-5d79-55b1-a58d-d1366a4f678b",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffdb101c-9b67-5ab3-9ddf-7060c8ecfbbb",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49b7e3bd-e953-5fb8-8f0d-ccdc09943a51",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d4a38dd-e1c7-55cf-819d-db5fe143a555",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518b70a8-06b6-5af0-99f4-d54969e265f3",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05ca344-d99d-5b08-9968-f0e1badbb82c",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc57c16d-e1b2-53e9-829c-aee492fcdaca",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb20b66-613f-52ef-950c-233ee082e903",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9babcbc9-f16e-59cd-b738-748354a4e187",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6eef765-20a0-5e0f-9faa-d7c43f9bb7e8",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70f05a18-6204-5bcc-ba10-ac9509eca10c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64fb7976-7337-5632-9ee2-779f1c57e4d2",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02605d13-a28c-5cd6-bd31-71c3df30bbae",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed1cc45-6656-5240-bf02-48fee50b94dc",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b98c93-0a76-5c43-9774-470d484e107c",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:979dedbb-6698-560a-96ac-6176dcc9181a",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a862f8-d96a-532a-ba87-88687e01ff3f",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86da93b-c538-52db-a5f3-b597729ae27e",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749c932f-df7d-537c-949a-8c2d97f8adc0",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac87b4f1-e036-548f-82c4-705eb116e6ae",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e73eb16-da18-5dc9-979c-ab5f141e519b",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46cf9c34-6b0b-5a63-b74d-168354a1dfbb",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9461054b-6a0a-5425-ba41-9acbbfbb23d0",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a2deae-6f6b-5583-aabc-7cfe8b5f15ea",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1902cae7-17f1-5b87-a3f8-4e0be98f69ec",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-server 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b30bd995-35e7-5805-ae17-0e423c3141e0",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3a3099-eb34-5dea-b445-7f55f2442cc5",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-server 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ebe921-b86a-5540-9de0-70932ae803b6",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa90a315-8c9f-52c2-8e85-f85d06265f4f",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-server 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f0ab92-13f6-51f5-9e90-96d0a284dcc7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdaae835-6976-534b-9418-4dbb867dd34c",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.1"
    }
  ]
}