{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6874da01-5d78-5710-a1d7-6b730180e915",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6",
      "type": "library",
      "group": "org.eclipse.jetty.memcached",
      "name": "memcached-parent",
      "version": "9.4.58.v20250814-tuxcare.6",
      "purl": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2eda2cee-68a6-59a3-a03f-34ad80ab1580",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d32a13-5976-585a-8862-4e1b175f06bc",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79468e48-0e42-5ecd-bc30-b14b6291d1bb",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a06d1e-f579-5d0b-87f1-d09ba1e22b8b",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9011808-57d8-51b9-aeef-e4dc5c0a86ec",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c715f86-3a6c-51de-9eda-bf40f47ac624",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27f5093-e82f-5931-86ed-29929af71554",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:770e87f7-a4ee-552f-bfa4-90801da6c053",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a350e89f-ff9f-5e66-8a11-9f2ba51b3bbc",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede17290-ff7a-5f84-81af-ea0f0c431978",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5863ee8f-c55f-52c2-a3cd-a531b529f3a9",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fced2a4f-e5b0-5081-a992-b5484d1c213a",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:668f0071-6c99-5bae-a0d6-d60258fcfb49",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88076e80-e844-5e63-b70d-67a12b092532",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badfd8a1-4cbb-5c56-99eb-e62e9eeebd14",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bb913fa-f482-52fe-9dee-72ca82210f40",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9e15010-b92b-5c4b-bf1d-b7f7be29d975",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b99498f-7d8f-5c1f-8ef9-ba1e79d635c0",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f7f302f-d498-5cc8-852d-76ceb9eb0ae8",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed4a515-27ca-574e-abac-1dd7cdc91e5d",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5acd462-b3ba-52f5-b2a0-5c1841ca8133",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty.memcached:memcached-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.58.v20250814-tuxcare.6"
    }
  ]
}