{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6a7fcff3-d3a2-5bc8-9153-7480add96bac",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2",
      "type": "library",
      "group": "io.undertow",
      "name": "undertow-examples",
      "version": "2.3.0.Final-tuxcare.2",
      "purl": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:44473592-5b54-56fd-b3c3-c52b3848f388",
      "id": "CVE-2022-1259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-1259 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ce5c67-60b8-51dc-b4b0-71018b78914a",
      "id": "CVE-2022-1319",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-1319 does not affect version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples. already_fixed \u2014 CVE-2022-1319 (UNDERTOW-2060) has been fixed in the target repository. The fix commit eefae287893fc79736c9573975a9c96c3161cab0 from April 8, 2022 is present and contains both required defense mechanisms: (1) END_RESPONSE reuse flag changed from 1 to 0 to signal connection non-reusability after errors, and (2) removal of duplicate handleBadRequest() call to prevent sending two response packets."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfda6cef-8d0a-5538-8e75-004e2cfc910c",
      "id": "CVE-2022-2053",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-2053 does not affect version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples. already_fixed \u2014 CVE-2022-2053 has already been fixed in the target repository. The fix (UNDERTOW-2133) was backported to all tuxcare-current branches. The code at AjpServerRequestConduit.java:206-207 contains the specific exception handler that catches RequestTooBigException and re-throws it, preventing the generic exception handler from silently closing the connection. This allows upper layers to send proper ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:712134b2-3709-589d-9295-0a94c4554867",
      "id": "CVE-2022-2764",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-2764 does not affect version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples. already_fixed \u2014 CVE-2022-2764 (UNDERTOW-2048) has already been fixed in the target repository. The fix was applied via commits 5f3b1f269, 05ab8777e, and f60972d29 on the master branch, implementing timeout protection for blocking read operations in UndertowInputStream."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31e0870e-91fb-557f-9948-70496acaed08",
      "id": "CVE-2022-4492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-4492 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d94437-c490-56af-b6ad-7e76072c6410",
      "id": "CVE-2023-1108",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-1108 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8493bd53-6f22-5f2f-89f1-42400c71dd81",
      "id": "CVE-2023-1973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-1973 is fixed in version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c61f279e-3ebe-5884-aab1-7ffb8b0fafe2",
      "id": "CVE-2023-3223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-3223 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:740533cc-5035-5509-a944-0323f26dde3a",
      "id": "CVE-2023-4639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4639 is fixed in version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fdbafa2-66e6-5168-8fb3-592a1e5d3ae5",
      "id": "CVE-2024-1459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1459 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c0cd92-3b03-5e9f-9bc0-5b3671ba9886",
      "id": "CVE-2024-1635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1635 is fixed in version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96b295e-1431-52ee-a50c-9aef0a2fe7f1",
      "id": "CVE-2024-3653",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3653 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:083e126a-5e0b-5649-983b-4aa7338c4565",
      "id": "CVE-2024-3884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3884 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffac94e0-5bb6-55b9-8cc1-882228ada96a",
      "id": "CVE-2024-4027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4027 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98880f7a-0853-55b6-b11f-ba3cc04a47a1",
      "id": "CVE-2024-4109",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-4109 is a false positive for io.undertow:undertow-examples 2.3.0.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b34726b-e2a2-549b-aae3-b6fdc137ab7e",
      "id": "CVE-2024-5971",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-5971 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a68c2a67-0301-5e37-8f87-c933e0d4b689",
      "id": "CVE-2024-6162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6162 is fixed in version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:239795bf-7c20-50e2-b3bd-ea603945f23a",
      "id": "CVE-2024-7885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-7885 is fixed in version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c33121-b87f-5980-878d-728a5c8d67be",
      "id": "CVE-2025-12543",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-12543 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ce34250-4304-5cfe-90c4-4430bfe709f2",
      "id": "CVE-2025-9784",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-9784 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5198550e-f897-596f-98f0-b280c5c62597",
      "id": "CVE-2026-28367",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28367 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ae9c3b-d1aa-5c37-9976-4034d36eef1d",
      "id": "CVE-2026-28368",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28368 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4f0f4f6-a3e0-576a-a98b-200ad20c657f",
      "id": "CVE-2026-28369",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28369 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e279415-1350-5efb-ad77-ee8c3db56415",
      "id": "CVE-2026-3260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-3260 affects version 2.3.0.Final-tuxcare.2 of io.undertow:undertow-examples."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.undertow/undertow-examples@2.3.0.Final-tuxcare.2"
    }
  ]
}