{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a26b3df2-1a45-5dda-9db1-f9e44dce5171",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-deploy",
      "version": "9.2.16.v20160414-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:44921174-6782-585b-822b-268225085b0a",
      "id": "CVE-2017-7656",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7656 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33af0689-b9d9-5d2e-818f-e0e64827260c",
      "id": "CVE-2017-7657",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7657 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2552c3c9-36dc-55d4-95b8-0a62e22f6602",
      "id": "CVE-2017-7658",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7658 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:373b757c-4ee3-55c6-9a0a-17f45c199daa",
      "id": "CVE-2017-9735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-9735 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b06c926-561a-5310-abf6-e470b098a93d",
      "id": "CVE-2018-12536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-12536 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913c21de-1f88-5630-931d-19b7a0908d7d",
      "id": "CVE-2018-12538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12538 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d371c22-a24e-54c5-a328-3f11e5684d46",
      "id": "CVE-2018-12545",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12545 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a509dc23-7138-53cf-80ca-7496999bb87a",
      "id": "CVE-2019-10241",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10241 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b580ce49-a13e-5d6b-a0ee-a26d8c4abcba",
      "id": "CVE-2019-10246",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10246 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9975157a-308f-556f-bc23-3077501fe6d4",
      "id": "CVE-2019-10247",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10247 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd14f70-db90-5fbb-852d-47b0119345cf",
      "id": "CVE-2019-17638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-17638 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b93c5a32-42f5-5b32-bafc-b0a23b1fd0dd",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-27216 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cafee06f-4e7d-5d4d-b9e6-5529a9bf37cc",
      "id": "CVE-2020-27218",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27218 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd89169e-1fc9-582f-9e80-5a967b4713b9",
      "id": "CVE-2021-28165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-28165 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c41897af-4e42-54e9-aa17-5261dc505cd4",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-28169 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:320d543c-2858-5606-ad8c-f175e03392e0",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32b8129a-2400-546b-94db-5c4cc36dc973",
      "id": "CVE-2022-2047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2047 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61297c6c-0e7a-5f81-a1ea-1addfd7f17eb",
      "id": "CVE-2022-2048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2048 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e589e8-ab04-5bb7-bd39-b80a62635519",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26048 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:206d1b74-d0a3-5d1d-b729-aa40d2333a92",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26049 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8fef999-1716-5061-9f95-c376b21bc355",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e3c4d14-8410-5732-9ad4-1b47173a1431",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2bc1101-5d8b-5258-8c94-1ac25f90239b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bff1fe0-201e-5172-b848-e2e7e74f4c5f",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-13009 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adcc7122-f25c-5363-93aa-cd731dd18a9f",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6ca98e-1b75-5f90-a696-b941e6388ae1",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6de5a4d3-1804-50ed-848c-73370b5ad739",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eabdeacb-ce95-5aca-97fa-10a8eb8a535d",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc5fc28c-c5b5-5699-9397-47fd2b5ff464",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-11143 does not affect version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy. Jetty version 9.2.16.v20160414 is not affected to CVE-2025-11143 according to advisories."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:353747df-2917-558e-959c-8ade1333e1ce",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d88710a0-dc97-55f2-9321-2c3b2ee342fe",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea614ac-142c-545f-8723-0331950de3a6",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae75252b-7a36-5e92-874c-4482bac47e92",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.2.16.v20160414-tuxcare.1 of org.eclipse.jetty:jetty-deploy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-deploy@9.2.16.v20160414-tuxcare.1"
    }
  ]
}