{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a15c8474-65d9-5703-b2d1-5f4d50f3660c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "infinispan-parent",
      "version": "11.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ce7d405d-e997-5fae-8b47-e9f41a22bd5a",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0cb7942-8f30-5b4d-86e0-cd7f79714ae3",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d170a49-cf99-511a-ae8d-8dede4bfad6f",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90558297-779c-505e-81af-97ca658bcaac",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b691e8ec-54e9-5575-b6f0-e5c04c8984d4",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9049a82d-3b1f-57f0-9308-2b7b03570c6e",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32b1fafb-4e71-5529-8d60-48f064776a06",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-5115 does not affect version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent. Version 11.0.26 is not vulnerable. Summary: CVE-2025-5115 (MadeYouReset) vulnerability patterns exist in the codebase (HTTP/2 WINDOW_UPDATE with delta==0, window overflow, and DATA frames on half-closed streams all trigger RST_STREAM from server), BUT the mitigation has been applied via commit a05e1d031d0 which implements rate control on server-sent RST_STREAM frames (default 128/second limit), preventing the DoS attack. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5a7cb7-c37c-5d12-b78b-d48096596031",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eae8277a-6c72-5c17-9486-517978119ad8",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d7f55cd-ed7f-573c-bebc-916a4a83bfee",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0af692f8-457f-532c-8f37-f22216af3ec4",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e4cc94-d0b6-5e51-b277-095088b0a655",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d853dd2c-c733-5034-be90-395b6e6e95c6",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86105bbf-39bd-58d3-a0f6-dd126995c9b8",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent. not_affected \u2014 Jetty 11.0.26 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12 where URIUtil.canonicalPath() integrates semicolon path parameter handling with dot-segment normalization and contains a slash state tracking bug. Jetty 11 uses a different architecture with separate decodePath() and canonicalPath() methods that correctly normalize paths containing semicolons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85aa4ce7-b72c-53fb-acf7-04ff0c4f7e3e",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 11.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/infinispan-parent@11.0.26-tuxcare.2"
    }
  ]
}