{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c5a44527-46c5-519b-a820-61ed1a7fe89a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.http2",
      "name": "http2-server",
      "version": "9.4.53.v20231009-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:62bb0dd5-b193-535d-9dd0-18d40dcbd7f3",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b267e0d8-a1f7-53d5-b959-bd59cbe7fe14",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d440cf95-e11b-5521-8d8e-2cbadfa46a56",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a30184f8-2b6f-58c9-8c8f-848aabff1c23",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7513cb28-0bbe-5cf0-93af-2cea712376ef",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f42d6f2-791a-5a0d-a053-7dd6c4b352e4",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35deb857-84bd-5927-8032-258e8dde36ce",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2785f1ab-361e-599c-ba4f-4534dcb2c096",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06af9c3-4015-5b9c-a418-6722788e184e",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01958f4-6273-5db7-ae81-d293dc6c47e6",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec345ce-ec80-51ae-ad32-c3d2be0b3d03",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40118429-18fd-57d0-b6f1-dd6893e65606",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6763 is fixed in version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f62cd9-e074-5f86-9a0f-290cbb842216",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22d4ae62-9e6a-57be-8fef-86138b74981b",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beefa32e-5865-5c37-b3f2-32d19fe279f6",
      "id": "CVE-2025-1948",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1948 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e55eab3e-cb56-5a1b-8ee6-fe9174425ec6",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:038f7646-b523-59e7-b078-1ab5e728ddfe",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8541378-0ca6-57df-ad58-ccb824c3f859",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b547513e-dcec-5a84-af4a-d8a59a41821b",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.53.v20231009-tuxcare.3 of org.eclipse.jetty.http2:http2-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.http2/http2-server@9.4.53.v20231009-tuxcare.3"
    }
  ]
}