{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:009ca3cf-5e5d-5d96-92a8-5d6e8c6d466b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "bcpg-jdk15to18",
      "purl": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2",
      "type": "library",
      "group": "org.bouncycastle",
      "bom-ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2",
      "version": "1.77-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-29857",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d53c45ab-e97a-5e58-be0a-1b57327b3023",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29857 is fixed in version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2024-30171",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d343a13c-1bfc-5010-9632-0c8fa044ad26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30171 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2024-30172",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1ddec196-164a-5963-a127-45bc70cab584",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30172 is fixed in version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2024-34447",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:92ec5061-d5ff-5ad4-b930-a2c4eec01fb6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34447 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2025-14813",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cca0acd0-45a8-58ee-b723-eae4c9ac5438",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14813 is fixed in version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2025-8885",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e540284-e568-583f-949f-948f2dc03e98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-8885 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2025-8916",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2cf32e4e-7c7a-581a-a393-ce7e0bb32c77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-8916 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2026-0636",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:db13934e-4ce3-5369-962c-e37190bac0a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0636 is fixed in version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2026-13506",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b8545f0b-ad23-52af-a494-33436f32d2ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-13506 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2026-5588",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:865f0589-ec4c-545e-ba4a-565d47c0dca9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5588 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2026-5598",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:63a488dd-3947-57d7-a951-787ab7516034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5598 is fixed in version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    },
    {
      "id": "CVE-2026-8763",
      "affects": [
        {
          "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7d5f86b4-4a5c-51e7-b979-7b6ffe1a4d3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8763 affects version 1.77-tuxcare.2 of org.bouncycastle:bcpg-jdk15to18."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.bouncycastle/bcpg-jdk15to18@1.77-tuxcare.2"
    }
  ]
}