{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:41444ab0-dac5-5496-a0b5-975f6f91ef44",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5",
      "type": "library",
      "group": "org.eclipse.jetty.aggregate",
      "name": "jetty-all",
      "version": "9.4.58.v20250814-tuxcare.5",
      "purl": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:75f1969c-0542-5ead-8a4e-4946464c2544",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b056b9-b1bd-54a0-8306-7b00ee88ee1c",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5de5590a-433d-5ca0-8d59-e6cbcd4db30e",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f007eda-36b2-5a4a-aefc-b4ff56cfb80b",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2bfcb7a-a8f6-540e-b3fc-03c9e04356e3",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e83881-f935-5822-88d4-0327295f3a5b",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3436b7-28be-5a5f-ae14-115367787f38",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc972205-7680-5383-89b6-912fdf9d9143",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2424bfda-7934-5e88-b45d-7de36084223c",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f721e7e-573a-5ce1-9b42-48866482f04c",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc44b9e8-d8c1-5d59-9722-708fefaeb16c",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fd83a7d-8e60-5d45-9cf3-1e594fde799e",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99460612-39b6-527f-8327-d80606689e88",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da3a9296-6ff9-5d4b-adae-787202e2fdb7",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4b203c2-2e75-5821-b65f-9352ff746320",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73e94864-2f47-5d4c-abfa-f09338484b00",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81cfc2ca-e778-5e88-b455-bb36f6a5c8f8",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828c7720-2792-5205-becc-bd3861bd3c3a",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8867084f-71f3-54fa-8919-a5ffe7ddcbf8",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e59f8a7e-dfae-51c6-b14c-e30d0a4c5879",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2335689-cccd-5d74-a77c-476ad9958314",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.5"
    }
  ]
}