{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f181eb24-1b12-5a87-86c7-7e623de9a4b8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "amqp-client",
      "purl": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1",
      "type": "library",
      "group": "com.rabbitmq",
      "bom-ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1",
      "version": "5.19.0-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-61634",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:26eb965c-003f-5a0e-ad22-3b31c762e637",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-61634 affects version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client."
      }
    },
    {
      "id": "CVE-2026-63335",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:402e0a51-aa0c-528e-ad0d-b7f46c024eac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-63335 affects version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client."
      }
    },
    {
      "id": "CVE-2026-63336",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3f1cfe9e-d145-5bb8-9816-896e198c2d38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-63336 affects version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client."
      }
    },
    {
      "id": "CVE-2026-63337",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dfaa91ba-bc2e-5a74-822e-39b277494e4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-63337 affects version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client."
      }
    },
    {
      "id": "CVE-2026-69219",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9a50122-9e5a-547c-b4c5-dec50ced95ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69219 is fixed in version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client."
      }
    },
    {
      "id": "CVE-2026-69220",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d645800d-4d9a-504c-b88f-8b2623ba957b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69220 is fixed in version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client."
      }
    },
    {
      "id": "CVE-2026-75516",
      "affects": [
        {
          "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:abd17ded-72ae-5fa1-a0b0-2de1a99fff83",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-75516 does not affect version 5.19.0-tuxcare.1 of com.rabbitmq:amqp-client. not_affected \u2014 Version 5.19.0 is not affected by CVE-2026-75516. The vulnerability requires a setFrameMax() mechanism that applies the negotiated frameMax to inbound frame size limits, but this mechanism does not exist in version 5.19.0. The target receives the INPUT (negotiated frameMax from Connection.Tune) but has no code path that reaches the GOAL (memory exhaustion via unbounded allocation). Inbound fram...",
        "justification": "code_not_reachable"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/com.rabbitmq/amqp-client@5.19.0-tuxcare.1"
    }
  ]
}