{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cf3f39c1-26e6-561c-8886-5bd2cab63d4d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-transports-http-netty-server",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c030f06c-b0b2-520c-8e95-79702efa262c",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:368a472d-5f37-5ba9-805a-3f3473e8d031",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6b1acc7-27eb-57d7-8d78-9b1ac54d3e42",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f85f1877-c2ba-599c-aaa4-269438f87a0e",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8085b6e5-b034-55df-99f4-1e73e1dc02dd",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5966c4d-9c66-58a4-b3ec-969d013d4a87",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74b269e-1421-54d5-9ece-ba345bf443f0",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a73da62-e728-587d-acba-c16873dc0ddd",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a07444ab-a6b4-5672-a1b2-7886fbf7321c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a88dedfe-66b9-5c72-98aa-83e75f57bacf",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bbfa2a8-05ad-582c-91f2-6412ba63543e",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7e033ce-4b0e-561f-be60-87a2ec649012",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:756169cf-01f4-5b78-a29a-4a386cb548ac",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6cbd50-1afc-5d57-a09d-3c15d88ed3e7",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ca1212a-a387-55b0-8b86-b7b243c7ef15",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52bfa777-c72b-5d78-9b5c-6015892d050b",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ace7c1-c1cb-5fee-9d1f-21d9ca3c153c",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89473b64-a46d-54af-84bf-3435605590d0",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c864ef11-8621-5955-90b3-355347d56dc3",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75033e69-ffc8-5fb7-a659-eb0e281ed035",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:620d261f-1591-50de-aa91-ff0daf06c802",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69dd2bab-bcfa-50ee-93f9-9e65da60d5a3",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8addff8b-0332-5a52-964e-136928b56ac5",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1457ea7d-c61e-5dcc-a546-8dfa6dd96d30",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602026bf-ff25-57c5-8c7c-6e2e7787390d",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae0388e3-37a8-5863-af10-a36f194587ea",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-server 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7018702e-ad86-5eb7-b5c8-5b729b12f4c7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d57c93-4f8c-5c57-b478-031acbe8d761",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-server 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c837c76-1c17-57f0-8972-f31cc2ffcf43",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3263c3b2-2ddf-5d7e-a542-4148f59b9ad3",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-transports-http-netty-server 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c55c13e-4efe-5af5-a1b7-d55c18963d14",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ca264be-136a-52f4-a14f-8d805b141d34",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-transports-http-netty-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-netty-server@3.5.11-tuxcare.3"
    }
  ]
}