{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6203d7f2-0b08-5e33-b7c0-a6b605e93598",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6",
      "type": "library",
      "group": "org.eclipse.jetty.fcgi",
      "name": "fcgi-parent",
      "version": "9.4.58.v20250814-tuxcare.6",
      "purl": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:59644709-9093-5152-8e53-2b4507ebb4be",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa46cd9e-80e1-50f5-b29e-618d46108ead",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0edd6f78-8496-5e1d-8172-ba2aede7442e",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e422f5e4-e284-5c16-9b82-fa100fff5ed9",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb01892c-eff8-5c8a-85c2-d5ef177c3ebd",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c91606d-c3f6-5126-9b0a-7922ad5cb6bb",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c3edae9-716e-5ce5-86e9-52c00a03f672",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79adc2c-cac5-52b9-a626-3b6e69638c46",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0259462b-7fe5-5b04-a9f9-e46d425330ce",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:830a2fe1-a56d-58a7-b0f5-a211d40f8d8a",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25ef2974-98e3-50c8-b1f8-a75ccf91a00a",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c15fbf1-3f70-5ab2-9870-d7113cf0271a",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3be4f84c-d0e9-555d-9c03-ba15b2860683",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d1b1b00-2844-54ed-9fd6-6c45ddfd8c45",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75cffe5-0adc-5eae-b824-491681609e62",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db44e0a9-b7c8-5ce6-885f-cd9498267af3",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0b7c848-af22-5b00-870e-e30ddc115ce4",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4551bdcb-022d-548f-9360-59b4eb42359e",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a6bb73-b51a-5d90-bc38-08d02886c9be",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb0c8044-c5de-55fa-ae71-363d371398d4",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef943956-79ca-542b-bd45-d930c5f9a100",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.fcgi:fcgi-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.fcgi/fcgi-parent@9.4.58.v20250814-tuxcare.6"
    }
  ]
}