{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:407d2a66-3163-5254-ac9f-e1db9f587c14",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-alpn-java-client",
      "version": "9.4.57.v20241219-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6d3b4bd6-b1be-5998-9c73-ff693192f5a9",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49df7ec7-a3b4-5cd2-9a43-726483453dac",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92e0b49-f353-5be5-980b-877eabae10d3",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a088fe87-e76d-54eb-bd56-1a81116fdc33",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1973ace-8279-55e9-a547-bb2496713aec",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ff1f8df-32b3-5019-b1da-ea42f7d3136f",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5535c51-f769-5966-9442-6151fcdb269a",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b667b416-2492-5ed4-9d42-8199924513bc",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:690614ea-14ca-56ad-aefe-e294783d249f",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d847f10-31a0-53be-b1b9-1b0df4cd8fda",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad052146-1de3-5994-a0b0-cd5e0064458d",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4ac6af6-5dbf-55a3-a9e2-e299f89f78cc",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:034a399f-1ac1-5d9c-af89-4c235345122b",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dc82d00-14f7-5222-b45e-c7663b6529c2",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a21b38a-e292-58bf-a174-7487f7871ad6",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8874be37-b600-54b6-83a6-ff02c13dfade",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eb81e8d-114b-5a9b-a210-da8ce629dc3b",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c858e5f-ec35-5f60-9366-c199f583efbf",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.57.v20241219-tuxcare.2 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.57.v20241219-tuxcare.2"
    }
  ]
}