{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:568e5983-99e2-5724-a3bb-15af650ea5ed",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-jspc-maven-plugin",
      "version": "9.4.58.v20250814-tuxcare.5",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a1637d1a-3975-5350-ba8d-3327a7197366",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a1d60c0-feeb-597f-a5ea-8e5f5ddb4d1d",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a05064b-ceb1-56db-aeaf-3d9bb292767d",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba3d377-cfb6-5e1b-aff4-4c9a8ada9de1",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7233434b-54ac-54bb-a3bf-aed9c726a102",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b38e32d1-7c92-565e-9d48-838f82e8fb9d",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44826666-f6b6-5218-beaa-0b188d5990c0",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee29a141-4bc6-5458-bf4c-9163254095e5",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6f95896-9c13-5d02-aa7b-93b3de14daa5",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcbdc0b1-1892-5c8f-a0b2-5261db5896cd",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d05b2d9-0062-5fe6-b2c1-f4f99245b95d",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dc81681-3dae-54e2-8847-fe0acb9c88ab",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58df6d18-e692-53c5-819c-3eec53331894",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db74458-4f3b-5d2f-8d9c-a3a97e75937e",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319ecd8d-6a69-592b-a187-cd709030b938",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4aecc2b-8e23-55c9-9001-158c6fa1bd30",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49c1ec71-8bd9-52e2-9408-5b0ceaadb78d",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1783382e-5240-5426-8c32-739869f37e9e",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64033d4f-07f5-5994-a7e4-e4a809eecba8",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5cf97a8-a0cd-5f8e-aec3-3a3a44dddba7",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98ccfae4-9bb7-5308-badb-6563129956f8",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.5 of org.eclipse.jetty:jetty-jspc-maven-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-jspc-maven-plugin@9.4.58.v20250814-tuxcare.5"
    }
  ]
}