{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:69f65141-4aed-5294-8278-80aaee679c2b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-servlets",
      "version": "9.4.58.v20250814-tuxcare.4",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:63425b17-252c-5b38-97fd-08aa56cf11d8",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac86a583-86da-59da-b176-c73b519d76f4",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20fe4abc-33ac-5a02-abdd-e8f560994ce6",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a12ea47-37d9-5033-9ac1-625753e5c530",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96439ee-8f10-5466-b674-dee68b6f5d07",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a321f8ed-b602-5382-8709-eb8bc8c439ec",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:925f1825-1210-500c-922f-d9eb36fb8f2e",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6bff9e-78e1-51a6-bfd2-80682bf5b9d5",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb33c318-16ae-5c8d-932a-92c93c0acdc8",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f39892e6-f725-5047-b9c6-42387b6ad0d7",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e46caf9d-29a4-545d-bce1-15ad7d781321",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc055ddd-769a-5de7-bf1b-ba829ff5e90b",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd0ba2e-3d12-572c-a33b-4ef478f63691",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed66d7f6-910d-535b-93af-08bc95b23dcb",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f25c4f2-0f77-5767-87fb-ff9ad49277a6",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec9f1d5-722c-5b7b-81b8-2ee4ccebc7aa",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b57421fe-273a-5f7c-936d-6c97dd5638b9",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6aa660f-6982-5489-b5fb-da1dbaaa34f3",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f8c5bb7-adad-57c4-a824-b7141d8631c5",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a18cb668-9b91-52d5-9eab-88dee05b9675",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03f6f0ba-ac52-57cb-9ae7-6fcce3d3656d",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.4 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.58.v20250814-tuxcare.4"
    }
  ]
}