{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:83247fba-e1ff-5227-bdd0-c4bdad06617c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.http3",
      "name": "http3-qpack",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dd134f96-81ae-54e6-8a1f-1f516ca4e184",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6698231d-36e0-5576-b169-3e0b24afbe47",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944c568e-ef67-5b70-9376-5aaeb5de198b",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b5332a1-5233-5e02-a62b-291736252c96",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a04ee5-c1ec-50b7-99ce-d75fab306d35",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74266e64-0235-5ad4-af48-795642809eb5",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb636758-35fc-5913-98e9-9ecd5be14709",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29e5cbb3-d436-5946-a4e1-3eab247d6190",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c025c31-433f-57c9-86e5-c8bdb9ce91b2",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:153f23d1-0dc9-56d3-8d61-09cd889e1a65",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b6f3c09-4e38-5575-8fbf-ee61fd72f42a",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f03486e-5d5c-5c6c-be76-f8828a1ee3f5",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e06c41f-c008-5183-a1eb-dbbf36af8608",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce4341af-f4e0-502b-99f1-63f98c19021c",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0583c674-51f1-57c3-984a-f8ce9ac61438",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b8b6b05-b051-5cd2-ac77-c46ce801b0c2",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103df57d-732c-52de-9891-6d078acdcf7f",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8c0642-df01-582e-aee3-ea2fb20dad78",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b202a8-ec07-5804-b040-42bffcfde59d",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f601ce21-b6a1-5a51-900c-2de428c139da",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5850a14-8fc6-59e9-aca8-1b66f6896cb8",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c085b48-28ca-580d-8e7b-1eee7a7affc7",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.http3:http3-qpack."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.http3/http3-qpack@10.0.26-tuxcare.2"
    }
  ]
}