{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:df951ff7-a7e7-571f-bf65-33f28d0fc0f7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.aggregate",
      "name": "jetty-all",
      "version": "9.4.58.v20250814-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3f4391c9-c81b-5e49-9d1b-427266d63e71",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d1d8c6-36f0-5476-8a06-2ea709f34cd7",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe8ddbe0-3bad-5f57-9be7-33fb5c9c5e05",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55254692-501a-57ff-b5c1-1f3aa57e7e63",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3adb95a3-9538-54d3-b2f4-f4cfb5be47da",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c244e12a-4fb7-5507-a582-9efec535b437",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e359a05-50e6-533d-965b-0f9701472128",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c92828-7074-515f-a6f2-82af0400eed0",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2df83a8d-90bf-5094-bb97-607c5fca7549",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dad19c2d-cc2d-5c04-9e3e-917b1fac74cf",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0490cbe-6d81-5e0d-9e69-3cc2b92e32ef",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c587d5-1c8e-5254-8587-903f77b2ad79",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b201f7-d66e-5738-80f4-cbff1a9321eb",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb91477-f7d9-5081-89f3-5b706c16043e",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6685945-5eed-50d8-bf28-a55c54c00c77",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d81ad06-f5dd-5aab-b3b5-cbdcd83f4b69",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c7a238-ae0d-5077-9c9b-e51b891b1684",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.2 of org.eclipse.jetty.aggregate:jetty-all."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.aggregate/jetty-all@9.4.58.v20250814-tuxcare.2"
    }
  ]
}