{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:83eaa8b8-c913-5463-bd0b-59a4a457097f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-ant",
      "version": "9.4.58.v20250814-tuxcare.6",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2cf29dda-e340-5538-a062-0c29c30c0706",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf925c8f-bfb2-574e-bf67-0dab87762bca",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21fa940e-3483-5d81-88a2-57043b5e2303",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db13cb2-a30c-5232-ab86-effd37d6a576",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4d1266c-f15b-5e4f-b205-99d63f917c77",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c50ed8c-c179-5b68-b621-c39bc6a95aea",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa401fbd-4e95-5e90-a59f-95e704bb39c7",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41c0a41c-c689-5624-81f3-625fcb847c9c",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7190a285-5f6b-53d2-a4d8-01a1f3611018",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d1af991-686e-522e-9aa6-ed90a9bcf576",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:840306a0-6041-5f6e-80c9-98c2fb2e6fbf",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8860be75-8293-51e1-b4af-45be8b976318",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03a71bb-ea0a-5682-b851-234adcf2fa78",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f476ad2e-a490-5293-847b-1e491a99bece",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f8bd909-6ab1-5cd2-8750-bc9b6b89e243",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca8e7c3-6a09-5bb3-abb4-e17780fa4cf9",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8482b7b7-3b3a-545d-ad33-e35be25265e2",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09cd4308-b429-5ce0-ad17-90b385f3468f",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0929d484-09e6-503f-90b1-1409f0aca954",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5c8b1a-352f-5cff-8f9c-a1464f70a5dd",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:071dd1f8-4b94-553a-9af3-3072c78210e1",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.6 of org.eclipse.jetty:jetty-ant."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-ant@9.4.58.v20250814-tuxcare.6"
    }
  ]
}