{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3b0c2dc7-9ecc-5fb9-8f6a-827983a6da30",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-home",
      "version": "9.4.58.v20250814-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:342d2cf4-a09d-5e11-82fd-25cfd20212d7",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e987a6f5-1d40-585f-9cdd-ef93ff3953da",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c189e3c-c8db-50c9-94fd-9c9a5c4b4deb",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dac6e3ac-6952-5fe3-9479-1574a1540a73",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a8fa020-05b9-5f02-9e44-e4af4fd87000",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9055f5b-9fbf-5e62-89e6-b3da9b1dafe5",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a716aa1f-fa35-576a-b63c-e05f8f0e2126",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e81b0bbf-ae31-586d-abe1-395e488f0f45",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98cebb81-1391-5fdd-9550-e7ba1daba2a1",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8efd519-f951-58e3-98ec-a4b3e4c54fed",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08298973-4f4d-5c37-a960-7e7fe83b0ff4",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe093c2-0791-55f2-9202-b435c044d6dc",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1899eb1f-b8f0-572d-b673-e2ffa7867585",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3e55d6-3b30-5234-8ec2-40421222252a",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1376c0-d8e3-514f-b15e-41a1dfd3a4be",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a53d73-6561-5d15-8e7c-32a048c95fc8",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbc818e7-008c-5e51-b551-0e156a780b7d",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e0d0444-1c6a-59a4-827d-10f4b8cd1d48",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:800bd188-b842-5f30-9d40-fcd258e82d1e",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc55ec8-0240-5187-8d3f-16d5d4b046b6",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72e0a3d3-e635-5ee0-9170-6035e52fe0c3",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.1 of org.eclipse.jetty:jetty-home."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-home@9.4.58.v20250814-tuxcare.1"
    }
  ]
}