{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dec19f89-ae40-5dba-8f78-eb05617c6dbc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty.gcloud",
      "name": "jetty-gcloud-session-manager",
      "version": "10.0.26-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1ec806ef-1101-5e5a-a3b2-77c330300ab8",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c040e54-5dee-59eb-bd8b-c7b153d61b35",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:243e7110-ec28-5188-83e2-6ad20db93051",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79e4f4bf-6084-5ca4-b955-a35ed251a754",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93bb3434-87fd-52d3-81fa-046c1858b63e",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc8f1ca-f0e1-5c35-abc8-1a4dd971e8bb",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ec66ae-835a-5340-9344-d80ae4d0c731",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cedd34d8-1e76-5817-8c1e-c9a64bb43678",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b4edc18-7576-5757-8654-4d3ab723cf49",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:167ad534-57e9-57f7-b2cf-2fe73e28cc05",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f9b5bf-d6bc-556f-a956-d46473923661",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44700df5-0d5a-5202-9fcb-81ef6f8a9790",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93ec3f2b-8995-5f77-8e8a-77c991644d61",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d912049a-2d52-5ea6-86bf-5f681990895f",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43258721-568a-5ddd-ae48-7c0b6d855976",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8df79366-d1e8-5225-8bdc-da8f1cdd66a0",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9da701-876e-5bbd-ad15-104541591651",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a00b86-3fa3-599e-bec1-ac748f1a7b26",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfb15571-f485-5568-a160-f1862cf8fc1e",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c8147c-48b9-5e78-b380-6971a43b0fc7",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6521d8a-d9bd-5b54-a1fe-2a2310e654b5",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5334dad5-9c50-5e67-bc7b-98dd39f7057e",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.1 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@10.0.26-tuxcare.1"
    }
  ]
}