{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:825c9a47-db83-5743-bfc2-0560e19a06cb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "activemq-log4j-appender",
      "purl": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2",
      "version": "6.1.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66168",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2979ef16-3e71-5d22-980c-bf594447d285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-33227",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:68aa21da-0a96-5f31-bf61-de0549b520ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-34197",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dd84165e-c451-59fa-8e7f-948cb0549bb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34197 is fixed in version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-39304",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:21ac9f1f-0807-5f51-8172-e4a02773f9b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-40046",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f4b6b917-d132-5b61-add6-c7a95270d6cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-40466",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7d6eb9a-2a0c-5d89-a43b-45b090de3d27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-41043",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b91e3265-3d84-5ab0-a086-5cc24ea0be53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-41044",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e5e7ed6d-74e8-5293-b434-2e906233e228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-42253",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de702b1f-bb2f-5550-b04c-ad68c09603e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-42588",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ba921da6-796c-563f-96e3-ef9b3f6e4808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-45505",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1f0807df-6a4a-5628-a74c-a7b5ec4a8bab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-46605",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cd836933-706a-5112-8118-524d8f834acb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-49157",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0dc55c6c-32d9-5b48-987a-bdfd0300fa39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-49270",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3fd00af9-4e6c-53d7-bd90-1cc8b057d752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-49432",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:074f5952-af01-580f-8300-c0fb57197625",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-49434",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b90fca76-2071-5dd6-86ae-87983de9023a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-49877",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b9f0e784-f25c-50ee-9b46-d4d2534f5c44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-50734",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:61a900b2-b4c8-5a59-a2b8-4ed59775dea5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-52760",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97a275d4-67a2-536e-a619-0827eabf7f80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-53916",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:976040cf-910f-5eb9-9676-92fc6f4e1a22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-53917",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32d67d6c-3e20-5326-a79c-fcfbaec4b16c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-54475",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f4bd3811-ed3d-51a1-858f-9c86e39db556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-59878",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c1ad98d6-592d-54ef-9d2d-a8ee1be513e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-61487",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5f55f2d3-2ff1-5a2d-b5a8-6f3f2366b4fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    },
    {
      "id": "CVE-2026-74761",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7d6dbd35-773c-5308-8362-ee086e79a141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-log4j-appender."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.2"
    }
  ]
}