{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d32bcb69-3057-5e86-921f-07bbefd34cdc",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "activemq-stomp",
      "purl": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2",
      "version": "6.1.8-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66168",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:259b10e6-03bc-5df2-b476-a1cfc77fc33a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-33227",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ec040b2f-40f3-5d79-a9cf-d727244c465e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-34197",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bb743559-9123-5ad4-af74-f0e02d3306cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34197 is fixed in version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-39304",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:809533b1-b575-559e-a3bb-3a3f5a7cd8bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-40046",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:556fb543-ec64-53b9-8336-cfd188760f96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-40466",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:19487b67-f026-5615-b6c8-f698b58d56c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-41043",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c50cb5d5-2301-5eee-86fc-5fd8912666a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-41044",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fdcbfa49-03d6-5968-b734-ad8d6a311a2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-42253",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:41f71554-6ac1-583f-bcfb-d9106cb6eebc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-42588",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:45224abb-1571-5cb3-8b1f-e1b641d0537d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-45505",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1582005c-9497-5220-a70d-6b5df32420b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-46605",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c337c541-864b-5727-9da8-b05b6175a03d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-49157",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:156cf3f9-a342-5c39-95bb-970ac5ce6e7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-49270",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c39e501-ef25-5fde-a7eb-7ef5bf80c154",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-49432",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c40f91c3-85ec-51c9-8e7f-98bf9096a126",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-49434",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b1d83123-d5e1-5705-898c-a64546d57be9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-49877",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:117cf063-1ee0-57b1-a3a3-447ec65835f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-50734",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6effc955-73f0-54ef-8b7a-27338e990d9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-52760",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ac978e6-fc41-570e-a16a-afbc16ed9405",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-53916",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:209d0b54-da2b-54f0-8bd3-6f4bfd83fa18",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-53917",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ef12119-e6bc-569e-b583-f9708f50d2c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-54475",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:698db4c0-ef92-5782-8668-7b12368a6ea7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-59878",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a9f94b42-b616-5c38-b28c-32ab479e6510",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-61487",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:648e0512-2692-5f5b-97e0-e3b6135aa409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    },
    {
      "id": "CVE-2026-74761",
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f363636f-aed1-5033-8e7a-dd3cce78bc59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.2 of org.apache.activemq:activemq-stomp."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-stomp@6.1.8-tuxcare.2"
    }
  ]
}