{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:09913470-f765-53ea-987b-dfd1aec9ec24",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "activemq-mqtt",
      "purl": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2",
      "version": "6.1.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66168",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:16beecd1-775f-5f0d-8db6-566ccddbf4b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-33227",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd7be717-f02f-5162-ae2c-73293a0f2138",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-34197",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d2da40d5-544a-51be-bfd6-4231a16df9f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34197 is fixed in version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-39304",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2384d267-3af9-5aad-8624-67932ec932e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-40046",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d88ea096-af26-5b0f-a579-2712ebccfeeb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-40466",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ba89926f-dbc2-5d34-a935-858773c298c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-41043",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:00611409-0aa2-5fe4-bdfb-852a069c5083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-41044",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f710902d-3481-5748-bbf0-77f8c68292f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-42253",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:59909131-6922-5a53-8e7a-9ff911e28874",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-42588",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a90e544f-f066-5717-9826-39a5a6364aab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-45505",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:868c953d-cb76-5f35-9aac-69f80d36ece1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-46605",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aa4ba7d7-5a2c-586c-a46a-a6d99f5635a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-49157",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4cbc2e94-1361-5963-b613-76afe893fc57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-49270",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:238d9616-b9e4-5317-b10a-876ace62c862",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-49432",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3005e16d-2720-5df2-add3-e84a25052ba9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-49434",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3a0d288a-f5cc-5d3e-b83c-e371892af59e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-49877",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d13f4f11-e1e3-5ef7-a276-69a95cfd9e4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-50734",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:80266042-f95f-579f-a9ec-304c87336409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-52760",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc99733d-5bc3-586a-9ed6-8e69a66f7b53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-53916",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f72eb15e-3d39-58e9-bcb3-50fc2b8f68c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-53917",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:408ab457-f7fc-509f-8514-6eee03f4d1b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-54475",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fdb8801e-e607-594e-bf52-f80535a3f5d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-59878",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:91f80d37-5956-5274-9c04-2a314744bbb7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-61487",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e216fbac-0764-5aa4-8bf0-938c00add032",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    },
    {
      "id": "CVE-2026-74761",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2a112eb-67ff-5c57-a54d-cc3a365741d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-mqtt."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-mqtt@6.1.8-tuxcare.2"
    }
  ]
}