{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5a59c9d0-da92-58c4-a5d7-67a473f2aa81",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "activemq-broker",
      "purl": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2",
      "version": "6.1.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66168",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1624a076-55ef-5589-869c-cbb1d6dcc6bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-33227",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d797c33-e2db-5ebc-b393-aae6d8040235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-34197",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b7be364-7ba7-515d-a111-22bf33eccaf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34197 is fixed in version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-39304",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fbee086f-29c6-5515-8bc7-d54f00fe8932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-40046",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dd4a0c3a-53c3-5a93-a3bf-a3982fe309d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-40466",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:680a9544-e2c0-5a3a-b9c1-9d3c7ff8a378",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-41043",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:94a68a9b-b5e4-577b-852f-338b8b4696c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-41044",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ed31f227-92bf-501a-820f-0f6162e63c7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-42253",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4f0d21e7-b41c-5fee-9164-baeb6367026b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-42588",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e51cd00c-6a8c-5e3e-95b1-1637c365ca5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-45505",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e169ff00-cb6b-58a6-ba66-2a9c6fe960ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-46605",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4d786a67-1ce7-58e2-8851-efd7fc32f7a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-49157",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a8de0a21-6d94-5ef4-a3bc-5757b2525af7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-49270",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:92783b7d-5eee-589c-ad81-3463739425bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-49432",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d46ece99-f91c-57bf-a0e5-5834f64ab697",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-49434",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ecec730-6474-58c1-b95a-30cda1c4df23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-49877",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c39eab6-847d-5724-a395-bbbf7e795431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-50734",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d0664bc2-aa6b-5cc1-9ddc-e96b573df645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-52760",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d74211bb-f311-5cb3-8ced-a8aed45fc4bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-53916",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ec167fd4-6b24-56f7-b4dd-c77b2bf1c3f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-53917",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:242f3f42-d9fc-5368-8e46-8d673d477629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-54475",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:547b97c9-bb62-5f58-b13b-547bf9bc600c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-59878",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5c3d81f0-4a62-5fb0-9712-d0288c84ee56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-61487",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7bdb763b-acee-5ac3-9b7d-60379e3259e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    },
    {
      "id": "CVE-2026-74761",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fde6ebfc-2672-5b3f-9f6d-71251102905b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-broker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-broker@6.1.8-tuxcare.2"
    }
  ]
}