{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2fc45d26-3791-55a7-bef8-ca41a33c8e7b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "activemq-openwire-legacy",
      "purl": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2",
      "version": "6.1.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66168",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:74588ecf-9100-5862-b373-ced829523fe7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-33227",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aade16f6-d3ea-5d2a-ab3c-32f37086606d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-34197",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f04641c2-3de4-52fa-811c-6b1585a7eaa4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34197 is fixed in version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-39304",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:62c07025-5387-5058-8e0a-4b900f2d7412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-40046",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9266b9fd-c324-5dd2-a03b-618d1a13eeb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-40466",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b56ac4f0-1f80-50f7-a3fe-afc8c60b43c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-41043",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2a830716-d7b6-5fb0-8221-c2601f472a9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-41044",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8364887d-18d4-508c-b191-7f1cb947959e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-42253",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6ee85640-23ba-5cd2-9b02-8cffc8448335",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-42588",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ed8df96-b35f-5392-9834-24cf5ab64e2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-45505",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0939deff-151c-52a6-b750-0f3e348f8ad5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-46605",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:79c4f8ef-18c3-57d1-bc11-94a36f0f0fd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-49157",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:744aff29-b952-5f19-9bf0-50e3ce59ff28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-49270",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dacb2568-c5c3-59f4-88b9-33531628cfdc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-49432",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7bca68a6-a848-58cb-87b3-82849305ff96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-49434",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b5cc4eab-2ade-5aff-8854-ff97998c6a85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-49877",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2916563-ae58-565f-a0dc-b708958d1ca7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-50734",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a24955e0-0e44-550b-a255-9ba66b9db287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-52760",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c94e9f1e-7d3f-59b7-947f-465a7d2c8420",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-53916",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e94fd2db-8f04-5001-8469-8f5b0b6d37f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-53917",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45620338-bc44-5d16-869b-7a484d7c587f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-54475",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7745108-2397-5f25-874f-abf73c74b1d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-59878",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0c6967dc-5fed-54d1-bba1-32df0b83ee78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-61487",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0daed9e3-9ff8-5d51-9d63-45a9b264b11a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    },
    {
      "id": "CVE-2026-74761",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:076d8e1a-8c2b-5bee-b05a-6f4d3e2a36db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-openwire-legacy."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-openwire-legacy@6.1.8-tuxcare.2"
    }
  ]
}