{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:65cc402b-f565-52dc-9bbf-02f07635e878",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2",
      "type": "library",
      "group": "io.undertow",
      "name": "undertow-servlet",
      "version": "2.2.33.Final-tuxcare.2",
      "purl": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c6247b56-7215-58fc-9a01-4e0ab04f6def",
      "id": "CVE-2024-3653",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3653 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ae76323-f1cd-5015-bb38-ac652a055ec1",
      "id": "CVE-2024-3884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3884 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:937b7677-1ba2-5b9b-8f0c-8d1aad4c93d1",
      "id": "CVE-2024-4027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4027 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe5a0b4e-7f55-579a-80e8-17e8779c8cd7",
      "id": "CVE-2024-4109",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-4109 is a false positive for io.undertow:undertow-servlet 2.2.33.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:def15eb7-4d24-5939-97d9-1193b3f7c7e8",
      "id": "CVE-2024-5971",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-5971 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f2faf9-876c-5fe9-a7bd-eb13e25843fa",
      "id": "CVE-2024-7885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-7885 is fixed in version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe19f616-f6f0-5edb-993c-5eefc11a555b",
      "id": "CVE-2025-12543",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-12543 is fixed in version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0d5394-1619-5b99-9c3a-634aa355849e",
      "id": "CVE-2025-9784",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-9784 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:267c3155-f564-5a8c-abd1-4f99684e6e36",
      "id": "CVE-2026-28367",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28367 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a03e440-10b8-5c98-af7a-b53e61bf6ffb",
      "id": "CVE-2026-28368",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28368 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eee1c75-af6b-577b-9f4f-d7d634050de5",
      "id": "CVE-2026-28369",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28369 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e5c0ead-ae99-5931-b9fb-f13e83eb77f1",
      "id": "CVE-2026-3260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-3260 affects version 2.2.33.Final-tuxcare.2 of io.undertow:undertow-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.undertow/undertow-servlet@2.2.33.Final-tuxcare.2"
    }
  ]
}