{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d1770b91-bc81-5d75-8583-a9357e972c0d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3",
      "type": "library",
      "group": "org.apache.logging.log4j",
      "name": "log4j-mongodb4",
      "version": "2.22.1-tuxcare.3",
      "purl": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f0f018f2-d833-5a2b-9289-df816ca3a9ab",
      "id": "CVE-2014-8180",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-8180 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff1957d-e5a7-5976-88b2-ab0726fa33f9",
      "id": "CVE-2016-6494",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-6494 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e9d5120-8bd9-5821-8f8b-7716cc228786",
      "id": "CVE-2021-32036",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-32036 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa5e6a8-1713-51e3-b7c3-b97e54a5c231",
      "id": "CVE-2021-38295",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-38295 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5aaf10a-0b2b-56ea-ac8d-b6398a1a12c4",
      "id": "CVE-2022-24706",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-24706 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92ade74c-1907-50b1-a80f-621ff5e0f0d5",
      "id": "CVE-2023-26268",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-26268 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db938cee-254f-55c7-8696-61e25cf8014a",
      "id": "CVE-2023-45725",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-45725 is a false positive for org.apache.logging.log4j:log4j-mongodb4 2.22.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96e734e8-32df-52a8-ad1b-c43ad9a98721",
      "id": "CVE-2025-68161",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68161 is fixed in version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb2fa0b-b338-5392-9694-77b22107bfc8",
      "id": "CVE-2026-34477",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34477 affects version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89654850-c357-5550-84bd-91a6d54deb75",
      "id": "CVE-2026-34478",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-34478 does not affect version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4. Version not vulnerable (per prereq analysis); terminalized."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:056f721a-a733-5f3d-85cd-119aeb699234",
      "id": "CVE-2026-34479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34479 is fixed in version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96b2b971-9cab-52e6-b92e-3b9181ded5da",
      "id": "CVE-2026-34480",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-34480 does not affect version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4. Version 2.22.1 is not vulnerable. Summary: The target repository version 2.22.1-tuxcare.1 is NOT VULNERABLE to CVE-2026-34480. While the XmlLayout feature exists, the sanitization fix that addresses the vulnerability has been backported and is fully implemented in the current codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e979311-3ca8-5787-b531-1468dd302caa",
      "id": "CVE-2026-34481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34481 is fixed in version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ad82b7-bbc3-5236-993a-ecb5accc845d",
      "id": "CVE-2026-49844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49844 is fixed in version 2.22.1-tuxcare.3 of org.apache.logging.log4j:log4j-mongodb4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.logging.log4j/log4j-mongodb4@2.22.1-tuxcare.3"
    }
  ]
}