{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5b98d73e-7c32-52b7-b98a-733b699b98e7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-extension-reactivestreams",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:151d458c-b70c-5f37-9a3c-01058972b1f9",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e9117d3-a93b-5b4f-869b-6637832c723a",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b011384d-7351-5723-b2a7-ea442c17aec9",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f7e9517-cca0-5a41-a44b-f271b1be63a3",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f264470a-5585-5239-932e-0ed6200fa5f4",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dae00927-d1f1-518c-a182-a41116a0af13",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d207add2-85bf-5f22-9dc5-f9cf4772e2bc",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec92446-0755-523f-8d5d-5de1bfe73cfd",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ae9a39c-3c3a-53b2-8c8c-f9cb8428cb55",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0177c63a-0ea9-58f8-8f50-fccd04ac2d21",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d2d152e-79b0-561e-a839-6532dccc558b",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59e91ebc-c0b7-5c42-8b3e-2f54c55f2ba7",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c1ecd01-5c7a-5d22-8f5c-cbe423210656",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b092ab97-d3dc-51dc-8500-b304182768a2",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0c446a0-7dca-5915-b344-f9dc342c20b5",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:580d71f9-2661-5716-a35c-a045104e5cbd",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31c53dc7-e531-51f8-878d-8db1f58ee85a",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ec22634-21ad-580b-9755-587d6a3c8236",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fae1ec6b-c017-5326-9b30-68780bbe38cf",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b582104-272b-5140-b449-52d233d9f5f1",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e45b2997-d076-50a9-944c-dc7e8176d89b",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed207f0d-be4a-5ef7-a9aa-c07d926d3cfc",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257d3059-7b53-5f5b-8cc7-ce82735d8571",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cdb5dad-2937-5232-a248-70272e422412",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13244a6f-2135-55ec-8865-7dfe5bd6f5b6",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4645741d-cbd0-5148-a992-2c07d7d77047",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-extension-reactivestreams 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d32bc405-2103-570c-9b46-484a817a7c6e",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a86c5f7-4000-5031-a9b7-454023ee0a34",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-rs-extension-reactivestreams 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d66163a0-ac75-548c-bdd6-8503b0918a36",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a1f28b-dc6b-550e-9255-d343c3af28af",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-extension-reactivestreams 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4676696d-4b91-5d41-a90c-081bb7019e5c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29aeff9f-aa90-59fc-9e9c-e801f86c6050",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-extension-reactivestreams."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-extension-reactivestreams@3.5.11-tuxcare.7"
    }
  ]
}