{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:661bf2e2-ab3b-52a3-a092-4a3c3b3eadf3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-alpn-conscrypt-client",
      "version": "9.4.53.v20231009-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:549b3b2d-af62-56cd-8fa0-e653c95c91b9",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e29ca8f5-3e98-579b-b61b-ae343a38c7f6",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0329711-ee15-5ac2-abfb-d57bb0fe015b",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2659c691-c741-5f39-811f-e96a88bdc2fb",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f0d8da-1dc0-5e1b-9756-0072f55f53bc",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5585398-eab1-5d60-8890-3ceaae3b83ba",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15125010-14dc-5474-b69d-d670e46544d3",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d3c440-4bdf-51cd-b517-0aa174d27c92",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bcf2624-d4bd-567d-8508-0de27e42b334",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d32995-0ba6-51fd-b81a-a14f99bb07f4",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe91be03-b04b-52f4-8a2f-4bedbdb3e095",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3219708d-acaf-592d-84a0-62814076d8a5",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23534d75-db4c-5a02-a7e2-40fb6b140107",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-9823 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94db32d9-3569-5ed4-b399-34a29b7e6f2b",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2470e4b-15d4-5883-b64b-735c98bc7018",
      "id": "CVE-2025-1948",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1948 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d307d15d-51a6-5423-a739-ab644d076693",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6991cfa-ca2a-5bd4-9608-51c47ba5279d",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:872cce2d-9217-5e48-abbc-045cebf64148",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15693e7b-8454-55b1-aef5-529d2c9cd3eb",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.53.v20231009-tuxcare.2 of org.eclipse.jetty:jetty-alpn-conscrypt-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-client@9.4.53.v20231009-tuxcare.2"
    }
  ]
}