{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c41d3bf3-abc0-57ab-92e2-3dea0e8df9cf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2",
      "type": "library",
      "group": "io.undertow",
      "name": "undertow-dist",
      "version": "2.2.33.Final-tuxcare.2",
      "purl": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:54e582de-6432-511a-839c-50ff54afdb1e",
      "id": "CVE-2024-3653",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3653 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eed15f6-6c57-55f4-8ef9-364cb679ba8f",
      "id": "CVE-2024-3884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3884 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d227bc4-c26c-51f1-aee1-9f4e2f77ddd6",
      "id": "CVE-2024-4027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4027 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56406059-7c01-50da-8b2a-dc7900887b6d",
      "id": "CVE-2024-4109",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-4109 is a false positive for io.undertow:undertow-dist 2.2.33.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5908303-adce-5f7f-92fa-c3686da8d3f4",
      "id": "CVE-2024-5971",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-5971 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a2aec5f-cbad-53a2-a3cd-1313ffe44b4a",
      "id": "CVE-2024-7885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-7885 is fixed in version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0336d3fd-9436-5cb3-9ed9-1c5413300019",
      "id": "CVE-2025-12543",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-12543 is fixed in version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0456ca-f58f-532c-8d91-4493428efcf3",
      "id": "CVE-2025-9784",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-9784 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005fa5d9-b7b3-5b3b-9160-62be9a3a88c1",
      "id": "CVE-2026-28367",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28367 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b32bcb9-4a88-5e62-8543-388bbffd870a",
      "id": "CVE-2026-28368",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28368 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95997769-99a3-5236-99fa-717c72bd6fdb",
      "id": "CVE-2026-28369",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28369 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca2b7566-d622-5d26-8efb-13f6f99ed438",
      "id": "CVE-2026-3260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-3260 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-dist."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.undertow/undertow-dist@2.2.33.Final-tuxcare.2"
    }
  ]
}