{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a647a735-76f2-50b5-8c15-d5725f4bdd5a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.demos",
      "name": "demo-spec-webapp",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:78f952d1-de8b-568d-b06f-19c4b1b1e6fc",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c8a698b-c9bb-59d8-ad57-1e3b059bcc45",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d822a355-062e-587a-8f8f-924f479417a3",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa838df-c1ee-5d27-96f8-37c204a9e9d4",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc606962-8873-5253-94a3-0fecdcb35978",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5ff4b9-cb9f-5202-8606-7ce922912857",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916bc451-6178-56f1-8bfd-0c638826baec",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b9e513-4f80-58f2-adf4-28e69e25b615",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea3da18c-f80e-5d52-8872-45f954a2b185",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79237316-7e00-5c70-9368-914e4760490f",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:618e0500-f182-5ce7-877f-49de914c5712",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfe50e10-7a60-55a4-82fc-9bd67c4e6077",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6791ad56-de53-5cd4-a913-b7be4cfbf8a1",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d81526d-c703-5931-82de-c40126dddf3d",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a32e69c-125b-5c33-b447-df0e7958f6e7",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e15a23f7-de76-54a1-b67d-4c8705290aa1",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fa82474-2cca-5e56-8dc9-1320d3f09e99",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0169448-5d35-5bd0-a92b-4bb55ca4818c",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5614459-7b71-5815-8347-45c25d8b6b26",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18eae4f7-dc3e-5b65-9a9f-83e072326e42",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0408963-bfd3-5d22-897b-3c8e889ddd63",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3deec7e2-d7f6-5fd7-993a-76904b01d048",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.2"
    }
  ]
}