{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dfe1c782-2844-50b5-a498-8200cb37099a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-security-jose",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5246b3e7-7486-5e05-9c0b-fa05efb77aa3",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a667db63-a037-560f-868c-e963159db48b",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c0f3b7c-05af-5858-a89f-1ee1170d44ac",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac75d604-6e0e-515f-aab7-ddac1449e0b2",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e90ae1a9-8a68-59d5-a9ac-459bb8e75199",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2588ee9-cec4-509d-bd0a-ac58f491cae9",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e3ff74-3807-5b26-9359-c032954d8d48",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5de40d0-ee22-5f4f-91b5-5763091d3757",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c31fb24f-93dd-5e45-b335-3c710a32c88d",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230f809d-9d50-522a-86b1-6f4813e0937c",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f511ce3-b2c9-5761-afd5-ab0d8719199b",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59f832d9-9279-530a-a6f0-f81e5fd07a95",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956feeee-c578-59d4-94e1-903efc5ff700",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c48a41a0-0041-5f86-8b95-52e542935be9",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbeaea7d-cf22-5a69-8fbc-639759495579",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0c669e5-bfc5-5ebc-85b0-f99ade37aee9",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46a8b0e8-958c-58ea-9355-142522e88aa8",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-rs-security-jose 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:403aad0f-e6a8-5ed0-8687-e88b34564780",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61d2dd24-6a3e-579d-8ca6-3efe302db143",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b8ac3eb-d7f6-5da8-924e-80200580255b",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b9e7aad-7648-5331-b3f5-50ced25760fb",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe187a6c-fb63-5a1a-8396-cec213ee973e",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8501c9b7-b673-5249-a19f-8d804a1310c7",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e38faa-a7ce-57b5-954f-849f4f3d5647",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81148b19-cc46-58f7-831c-c759bee7adbe",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd484d94-707e-526a-9f65-13719317bb99",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-security-jose 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5cf6d50-dd3e-52fb-97b7-177b285480a3",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957408a3-96a1-5e08-831c-6a11fa54c2c4",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:680c9291-75ba-5d37-84b2-c0c0138bbbe9",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:410b6cd3-d705-50e8-aa93-81e43e0514b7",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-security-jose 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df105d65-3930-57d2-9564-d37fffc8f336",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2fcb4a-82d1-5dd1-8c65-fbc4d9d8ffce",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cadf859-39ab-5365-be8e-3e66f894a5b4",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d1481e0-1094-59c5-9d71-0b2b0141b094",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-jose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-jose@3.5.9-tuxcare.5"
    }
  ]
}