{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7d5c30a7-50c5-57d2-92d8-0ced06c639aa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "activemq-karaf-itest",
      "purl": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2",
      "version": "6.1.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66168",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c0682057-5c72-5d51-b866-70eafe48aa5c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-33227",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4c7052ea-0409-53b0-92c9-c8f81da59c03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-34197",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cd5896ad-344f-5d22-b262-ffd5881af0c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34197 is fixed in version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-39304",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6bafc7db-f867-5cef-898e-c0e915034a31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-40046",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:24d03509-8873-5490-9464-720837aec65a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-40466",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e0baf1ae-ae26-556d-b252-e66ed62a275f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-41043",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b8bf5233-0673-57f3-baf1-cfef511cac6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-41044",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b1f98d1d-674b-5a7f-8059-9ef799b0f55f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-42253",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0059f7c2-c58b-5b23-8c2d-e77b0d6d4e94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-42588",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:16976df8-06b2-57a0-bf2d-19b5d66d39a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-45505",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:13b2c913-5218-539b-9050-c498e59c9e05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-46605",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e9dc448-acaf-579b-9fb7-c84aae49d5e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-49157",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:edc078c0-311e-53e3-9f34-8f57947a8291",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-49270",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f0722c84-73d1-5c81-812b-5b544c3f7b57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-49432",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:337f9c08-1518-5426-ad44-0bf463dc1a00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-49434",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00230433-f0e2-5d1e-889d-49a9c5fb9a5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-49877",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a7cec066-40da-5c18-b33c-eab24f63a7bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-50734",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:067e8536-198f-5f38-a682-c1028e2c8a9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-52760",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af317e82-3bf5-561b-8c7c-2a49e10297f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-53916",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:72000e6f-3b42-56ce-ab72-db5e6a8bde5e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-53917",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:df97d01b-4840-59fd-a0eb-162fe341c41f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-54475",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2147da6e-36c3-5f26-b61d-0067ce5ebec5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-59878",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:176760a7-98cb-57ec-9da3-42cb5f5c64d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-61487",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:41f1d030-7c62-5784-8046-19bc7ab79c6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    },
    {
      "id": "CVE-2026-74761",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bca9da8c-73a0-53cb-a0da-a9233fe9e4a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-karaf-itest."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-karaf-itest@6.1.8-tuxcare.2"
    }
  ]
}