{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f7267dcf-0bc6-51f9-9ce4-cf0a4df0e8e6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2",
      "type": "library",
      "group": "org.bouncycastle",
      "name": "bctls-jdk14",
      "version": "1.64-tuxcare.2",
      "purl": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7b68f359-ec96-5c2f-ae21-7da498f4a34f",
      "id": "CVE-2020-0187",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-0187 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec80a0f-e78a-53be-9311-b4592a3e52d3",
      "id": "CVE-2020-15522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-15522 is fixed in version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80e3162-a6be-584f-b7bc-57285122b89e",
      "id": "CVE-2023-33201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-33201 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7bc05d5-633b-5816-a78d-66e0dbc488a3",
      "id": "CVE-2023-33202",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-33202 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a387a57-14cb-5a19-8b13-fb62f4e7fa2d",
      "id": "CVE-2024-29857",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29857 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c2f3b3-0275-508b-b3bd-1b7a1b97691d",
      "id": "CVE-2024-30171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30171 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47621b9a-ad81-5332-a381-8e0fc66c904b",
      "id": "CVE-2024-34447",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34447 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a035b16-9b65-5ba3-ae1b-bdedc34950b6",
      "id": "CVE-2025-14813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14813 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b302ef34-1316-5e95-aaae-89278b9e8e13",
      "id": "CVE-2025-8885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-8885 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b68eeb-f24e-576a-9fbc-b099c9903580",
      "id": "CVE-2025-8916",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-8916 is fixed in version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2b9058-ac54-5b3f-bcba-3011b574a7dc",
      "id": "CVE-2026-3505",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3505 does not affect version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14. Bouncy Castle Java 1.64 is not affected by CVE-2026-3505. The vulnerability specifically targets OpenPGP AEAD encrypted-data packet processing, including AEADEncDataPacket, BcAEADUtil, and JceAEADUtil, which do not exist in version 1.64. Although Bouncy Castle Java 1.64 includes OpenPGP functionality, it does not support the vulnerable AEAD packet type and rejects packet tag 20 as unknown"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65492a56-4663-594e-a9ca-8bb8aafc83c4",
      "id": "CVE-2026-5588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5588 affects version 1.64-tuxcare.2 of org.bouncycastle:bctls-jdk14."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.bouncycastle/bctls-jdk14@1.64-tuxcare.2"
    }
  ]
}