{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d28a40d7-4754-5b4e-b0b4-2e640c0d16ef",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.http2",
      "name": "http2-client",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a983b326-aeef-5a12-93d0-8809851f2c58",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:362f5e82-9105-5d46-8109-f0c845492fc2",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86a6c6ec-318a-5d88-a60a-12fc7c60ae89",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5457170b-b816-5ee7-82f1-f37f071abcb5",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0030fc5e-c2d0-5675-960d-f54210a93af3",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9262be50-05c2-57ba-ba3d-615c8952b4d7",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4148b0d-8a0a-5e98-92b3-0655c5bca938",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca53440-78e8-510f-acdc-9b7c907948c9",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f42f810-af89-572b-8830-28f9db3d4ce9",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:878df1c5-cad4-5e5e-a831-699d83cba84a",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5914466-b976-5007-ba6f-77f28766c6fa",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59cf405f-be64-5ac0-bb4e-7418910e6fd9",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c97b44b4-b4bf-5c18-b581-4c9b35a9a148",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f09d6a2-ecea-55ee-8516-f562b042a486",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49b37efb-a25f-51f6-aeab-fb7c56edafb1",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9e7abaa-4a74-5f1b-88c5-e8db9a9d92d4",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be5136e7-6363-5f5e-bdc3-40d59ab757bb",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69e8b61b-9dc1-5f57-84b4-46c25451b256",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac88d2a-7813-5381-9ed2-70d3334963b1",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6109f155-6cc4-5838-9109-dba3a1e2396b",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af188c5-66c3-56ae-8266-f79b97fb8d7f",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a280f62-76d3-54ba-aaad-1ddc315bb9b1",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http2:http2-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.http2/http2-client@10.0.26-tuxcare.2"
    }
  ]
}