{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7e199dd5-8c45-5008-8735-300e7f4884a8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-servlets",
      "version": "9.4.57.v20241219-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:faeaf09f-4885-5287-8712-243534bd932b",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efb06b23-e1bd-532a-a9b8-cc0dc476e262",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a0d2d3-915d-5e9f-b550-efd4dbcd43c2",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88b39996-6a3e-5e7d-9e85-80d759255937",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26d47669-7048-5212-869c-8cf7f8f22ab1",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:763582b7-7613-5993-b2f7-676b7a1acd8e",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee9362e-158c-5355-8a2f-34d6fbfc241a",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e0b4ed-422c-5283-b8fa-31745a14253d",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9f5f75b-0d44-5f42-909b-e2f312e5d5a4",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:451d78d0-f53e-5148-823b-e1303560b9a6",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b600ec9f-76d5-5ef8-a228-fb5922e1b0fb",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35b595b0-ab3b-5364-bbfc-8b64dcbb071b",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c674a809-fea0-5523-aeb1-306b8d4093db",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10bba87c-b855-5942-b717-cebc4385a43b",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34cd979-f81c-5aee-96bc-d8fe05f313e6",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b1fc2ae-bf2e-5975-9fc8-8d0c8d49930d",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44bef01-d1bc-510a-af83-96cb570f3e97",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e3b088a-654f-5563-b1db-2c930261f3e5",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.57.v20241219-tuxcare.1 of org.eclipse.jetty:jetty-servlets."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-servlets@9.4.57.v20241219-tuxcare.1"
    }
  ]
}