The Karaf Specs bundles (https://github.com/apache/karaf/tree/main/specs/javaxml and https://github.com/apache/karaf/tree/main/specs/javaxmlws) bundle GPL code which is Category X. These bundles should be removed (using alternatives).