{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:19694064-cc5e-5619-8fb1-793284b9f3f8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.services.ws-discovery",
      "name": "cxf-services-ws-discovery-api",
      "version": "3.4.5-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:83ae674b-bf8b-5cd8-aa23-9133633e172e",
      "id": "CVE-2022-46363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46363 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64e52cb1-19c4-5ca5-afeb-492d59c13dc7",
      "id": "CVE-2022-46364",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-46364 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a704572-2db3-55cb-b8c5-dd1f5a51e42c",
      "id": "CVE-2024-28752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28752 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cda4bb43-dcf4-5bc3-bd2e-d704cf4ce1d0",
      "id": "CVE-2024-29736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29736 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f42f5b-5af6-5bbe-a685-ceab20785be6",
      "id": "CVE-2024-32007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-32007 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce848d0-82f0-5a63-9eca-78d20cb30ffd",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-23184 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e88df363-bc31-595d-9ccc-7d6a22c7fd52",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48795 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api. not_affected \u2014 Version 3.4.5 does not contain the vulnerable code path. The CVE-2025-48795 vulnerability exists in DelayedCachedOutputStreamCleaner class which was introduced in version 3.5.11 (September 2024). Version 3.4.5 predates this component and lacks the leak detection logging mechanism that causes the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d77f01e-d0b5-5aae-ab61-99f243f8a234",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af700be7-dce7-5f34-8528-fccc3904a20e",
      "id": "CVE-2026-44417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44417 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f8a99d4-f064-5681-bad3-d801cac5cf8a",
      "id": "CVE-2026-44618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44618 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61259547-fc46-5957-952e-fc15cf2c42dc",
      "id": "CVE-2026-44930",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44930 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad74d18c-5008-507a-898b-e1abcfc6079a",
      "id": "CVE-2026-49875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49875 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef54a87-0877-55f5-bb08-5e6984603b5f",
      "id": "CVE-2026-50623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50623 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73fad996-92d8-5ae1-a76e-07cdbe1d1794",
      "id": "CVE-2026-50627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50627 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74815c63-3309-58ac-b721-1d613039cc5c",
      "id": "CVE-2026-50628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50628 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f0d75b7-03af-53fc-a9b9-7c7d2a95de72",
      "id": "CVE-2026-50629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50629 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a2b691-557f-5b26-8976-049c1b0a9c51",
      "id": "CVE-2026-50630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50630 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c8989d3-d175-5008-b8ac-c80bc23de8c6",
      "id": "CVE-2026-50631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50631 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c352a6-9063-5e25-bc42-d0e35537e2f6",
      "id": "CVE-2026-50632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50632 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675fe863-d751-5a19-8142-00209b46e738",
      "id": "CVE-2026-50633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50633 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:244c0d1e-f5d8-5c36-92a5-392e886344f6",
      "id": "CVE-2026-50634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50634 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a08184-e248-51be-989e-52de9bcbc70a",
      "id": "CVE-2026-50645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50645 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af340eff-c74f-5da8-a583-207dd70ad3d3",
      "id": "CVE-2026-54225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54225 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c84c27da-1a2a-5179-9053-d33fc8b03c36",
      "id": "CVE-2026-57817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-57817 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b204f335-38e7-5708-8d37-3c9752ed8408",
      "id": "CVE-2026-57818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-57818 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:718da010-4dc3-5763-8e9b-eb743560ba96",
      "id": "CVE-2026-57819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-57819 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a719d72-d478-5939-bb66-0a5ca15f901f",
      "id": "CVE-2026-61466",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61466 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3506d34-18b0-5256-8c12-7dded812c797",
      "id": "CVE-2026-63687",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-63687 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec760f58-327b-5ed7-83fc-ac5703b3ce11",
      "id": "CVE-2026-64958",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64958 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9f1d362-63b0-5f59-b0ba-2d656d5fc559",
      "id": "CVE-2026-65432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-65432 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3680ef6f-0540-5b22-b7bd-cceca9a16af3",
      "id": "CVE-2026-65583",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-65583 does not affect version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api. not_affected \u2014 Apache CXF 3.4.5 contains the vulnerable code pattern (empty validateSelfIssuedProvider method), but the vulnerability is NOT exploitable in the default configuration. The supportSelfIssuedProvider flag defaults to false, causing self-issued OIDC tokens to be rejected by normal issuer validation logic. Exploitation requires explicit configuration via setSupportSelfIssuedProvider(true), which is..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16b7aac9-8d24-58ff-a8d3-806ae72882aa",
      "id": "CVE-2026-66909",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66909 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:454d4b1d-1ca2-578b-821c-b6b6ed761499",
      "id": "CVE-2026-68079",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68079 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ade4d73b-cee4-52b0-8fff-570145f6c55c",
      "id": "CVE-2026-68481",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68481 affects version 3.4.5-tuxcare.1 of org.apache.cxf.services.ws-discovery:cxf-services-ws-discovery-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.ws-discovery/cxf-services-ws-discovery-api@3.4.5-tuxcare.1"
    }
  ]
}