{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:de146aec-92e5-500c-ba38-b610540105a9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "name": "artemis-jakarta-server",
      "version": "2.26.0-tuxcare.2",
      "purl": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7ddc4f80-c2f4-566b-98b3-8c6d15d2eb13",
      "id": "CVE-2023-50780",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-50780 does not affect version 2.26.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-server. not_affected \u2014 CVE-2023-50780 targets Log4J2 MBean exposure via Jolokia endpoint. Target version 2.26.0 uses JBoss LogManager instead of Log4J2, making the Log4J2 MBean vulnerability pattern inapplicable. The logging framework migration to Log4J2 occurred in version 2.27.0 (ARTEMIS-4020), after this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6cb4ff-614b-5ded-a3fc-66946581d9e2",
      "id": "CVE-2025-27391",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27391 affects version 2.26.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b55be9b3-c37e-58d0-bca1-bad81cbecd71",
      "id": "CVE-2025-27427",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27427 is fixed in version 2.26.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d0a8be-c444-54ca-96c4-b2302ecbd140",
      "id": "CVE-2026-27446",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27446 affects version 2.26.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f18952-0e1a-5fba-848c-69545c2a598e",
      "id": "CVE-2026-32642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32642 affects version 2.26.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-server@2.26.0-tuxcare.2"
    }
  ]
}