{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c27d4b50-ecf0-50ef-b3ae-979e695ec1c2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1",
      "type": "library",
      "group": "org.apache.activemq",
      "name": "activemq-log4j-appender",
      "version": "6.1.8-tuxcare.1",
      "purl": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:604c754e-b4f6-587d-b2dd-67b812475479",
      "id": "CVE-2025-66168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f258a4-2273-57f5-b7ce-92792e7115a8",
      "id": "CVE-2026-33227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33227 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29228cb2-a45b-5adc-a57f-299db5a1ff87",
      "id": "CVE-2026-34197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34197 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a14fbd40-291f-5622-8f03-a48805765fa8",
      "id": "CVE-2026-39304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39304 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f0770a3-c96b-5f55-9184-b99748e8cdeb",
      "id": "CVE-2026-40046",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40046 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2405e912-6f82-584d-b5be-64b291fb2ad8",
      "id": "CVE-2026-40466",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40466 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea5a1e0-bd5e-53a7-bcec-d2061e44ef85",
      "id": "CVE-2026-41043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41043 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e30567f-175f-5a43-955d-7b28080a428c",
      "id": "CVE-2026-41044",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41044 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5a2d0b2-df50-507f-a3eb-3f59bfe79bd3",
      "id": "CVE-2026-42253",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42253 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7901bdc-8025-5051-9a47-1522bdeff3a4",
      "id": "CVE-2026-42588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42588 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a884cb45-7837-53bf-997d-ad35a15fa909",
      "id": "CVE-2026-45505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45505 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bb64a0d-8b9e-5484-84cd-49020f93e429",
      "id": "CVE-2026-46605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46605 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12fcea16-cf61-529e-a81e-369a085c680a",
      "id": "CVE-2026-49157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49157 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80af4b20-fc80-555e-9d3a-463267cb21b3",
      "id": "CVE-2026-49270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49270 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75392c8-56ac-5114-a0fb-69789422c581",
      "id": "CVE-2026-49432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49432 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb53632-be46-512d-b850-f59847b7e655",
      "id": "CVE-2026-49434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49434 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f952d0-3987-5675-984e-0b995f5d5f0c",
      "id": "CVE-2026-49877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49877 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9f926f-d747-5a75-9c2e-d14cd9e0e24f",
      "id": "CVE-2026-50734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50734 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f8da193-37dd-5639-a56a-9b65d494e40b",
      "id": "CVE-2026-52760",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52760 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f2d7778-d121-5ba0-84ef-79f35c6c51b4",
      "id": "CVE-2026-53916",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53916 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49b73699-492b-54ef-8e85-5796fb3ed838",
      "id": "CVE-2026-53917",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53917 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4fe2aee-a987-56d9-9de4-7b31f6f3f73f",
      "id": "CVE-2026-54475",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54475 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a012a69-41e6-5784-a141-252dbabfff55",
      "id": "CVE-2026-59878",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59878 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4813060f-25eb-5932-bcf9-1cbbc2227f1a",
      "id": "CVE-2026-61487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61487 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6231aae9-61e6-5d49-958b-caa878deb04a",
      "id": "CVE-2026-74761",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-74761 affects version 6.1.8-tuxcare.1 of org.apache.activemq:activemq-log4j-appender."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/activemq-log4j-appender@6.1.8-tuxcare.1"
    }
  ]
}