{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:716dda12-8444-5c41-a3fa-dbdbe3f7b062",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.fcgi",
      "name": "fcgi-client",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1ca17703-d565-5e0b-a6c4-f94d4f670a87",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e783ee70-a53e-5067-94aa-9a54d2c5f1c7",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd48c1cd-41ed-5e40-a4cf-fc362ff52103",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73d53424-5ea3-5ab4-8025-df0c1e3d6d2f",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6a7b17d-b64a-5a9e-bcdf-fb475ce7f2bc",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:105404b3-f198-5e01-a18b-b26885d804f7",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad0e31d2-22ed-54a1-9e03-482af4613001",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe47970-8a1f-51e0-aa74-3a668332247e",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de0a1c10-9064-551b-aa75-7e393db8889e",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1a95e7-c607-58b1-921b-ef0080e2691a",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b37674-4567-54e1-ae28-91acbe5338c6",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3632eeab-cb47-58cc-93ff-28382adac5b8",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b89a38ed-f664-5e87-aada-29cf43d5e3cd",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a3bc517-0c0f-59b8-a380-d6638fd561c8",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7787022-3bbb-5130-9b83-03275d1b5337",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70e7310f-9e65-5575-945a-a9cf39a1c34b",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:460708c2-9c67-5b9b-95bb-b48545654ead",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde74ec4-f1ab-5d20-9fbf-696fe0ea9443",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e0ad54e-753c-5d05-8f6a-ed9d314fb6b3",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b707ac7-13a0-535c-9507-f7c7d67284fc",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d669cb3-0bc1-5bf8-885b-af1b6185d88b",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:879a9adb-9040-56ea-8d39-cee920b36dac",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.fcgi:fcgi-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-client@10.0.26-tuxcare.2"
    }
  ]
}