{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9ee6e485-6804-5705-8b10-c1d95578de9b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4",
      "type": "library",
      "group": "org.eclipse.jetty.memcached",
      "name": "memcached-parent",
      "version": "9.4.58.v20250814-tuxcare.4",
      "purl": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6f215fbb-aab9-5176-abb6-aa35a279db4d",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:508d2643-43b9-57db-a09c-ac0c842ffb3c",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0521715-859c-5979-8428-83ab472cbb0f",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b4a2ab9-3104-57ff-9acf-c0ae83478361",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fef8ba44-fbca-50cf-b978-b79870f3ab60",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:812836a7-1a59-5ba7-ab60-eac0d1c23df1",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3369dfb9-3ad4-56ba-96c1-9a8e6d4646d0",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19b8905f-7c2e-521f-b489-8d0794a36b82",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42350f5-2a80-566c-8257-e093a40df749",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9700a72e-71f2-5cc7-b062-7f79c8505c77",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c6fdc4-37b1-5d74-a856-7bff715afc4e",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ccaddd5-6cbf-5f37-a37d-e70566a7a587",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73413352-2a3a-572c-a652-2e2fe38caf94",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d9a8181-dcc4-5d69-8896-6ccd5544cf8c",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf586ed3-9a77-5bf5-bb71-5bb0b516a918",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7868a805-9339-52c5-9c93-9f1de1a6ee22",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae5bdc8-d547-5b44-9568-c2a4b510fbc0",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a91fbd76-0870-531a-b59e-779c353aa1a9",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c871e0-7050-5e41-a0a8-b45cc36746ac",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14527d41-e2cc-5a49-a515-2cf7e630c131",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4da38aba-1026-5cbb-a9c1-204de80bd9e0",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.4"
    }
  ]
}