{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7e82c514-1fa9-5698-a53f-840e39b1ae8b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.websocket",
      "name": "websocket-parent",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8e942038-13c2-5e88-9135-f60ca01ee83d",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e815bd18-ad59-5a5e-b53f-cc7c679d0a3c",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5faab5a-c5a8-5661-9157-e289412de7db",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ebf630-e991-5db0-9ad6-f8b75dd4ba96",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73ca704d-1719-555d-871d-5cf8b46101a1",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37294733-6c8c-5b7a-aab4-237146187fe8",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3de56445-e421-545b-b187-394da08c548c",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1872c03-a7fb-51ac-934a-76dae8b6be73",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4522c0-8554-5476-aecb-84b63f0812e0",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:445787b9-150c-5f89-be3c-59c1514f510d",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5a323a-5f5b-5cb7-992a-90e8dd285c14",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf40b4a4-be86-54d9-bc8b-ee79b58f89d8",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d2e53d-d542-5998-9987-94f1f4fb91c1",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:843c13ef-b3fd-548d-a18d-78e8df9430ce",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f87c753-bd5a-59d0-b885-ec889c966def",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68bd4086-87b6-5ebf-845e-7dd244a2138d",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26d9a6ad-5d48-5f66-acd4-6ed01b723304",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5663965d-6ad7-577b-8a6d-dc3e096e04d3",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6daa0df5-07a1-5af6-97ae-e0a83bac6ca8",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbaec0b0-2b8f-58db-b43c-cdcdde82b764",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c753e07d-217d-5b2d-8ee9-a4240e90df9d",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ec5107-d578-5620-ad94-a6d4bd75bd73",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@10.0.26-tuxcare.2"
    }
  ]
}