{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fd5c2dab-9df3-524f-893c-0060edf7d62a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "infinispan-remote-query",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f80d3e1d-0b76-55e1-841b-23e069efcb13",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b0a332e-11b3-5a3d-9aed-9576f9f1a5ae",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78c8f14b-8db7-52b1-bc42-23ebf3219051",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54351d0e-f034-5f29-9e64-5e6fd09fd573",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc584b2-c774-5092-85f1-542c8c93433a",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8a6f01e-b442-5130-aa39-441aea2209a3",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9040f11a-7b8c-5c2c-9478-cc97874a084d",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac6dcced-9478-51c0-9381-28446ee45959",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:317590be-c62b-5dc7-af22-49141f75c6e7",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e5ccd56-3fb9-5ed9-9770-4ff25761a39b",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3afeefb3-0204-5add-b8ce-6ac7e3392b2e",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea196c5-cba9-5be4-acd5-36032f83465d",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b9f98e-9a04-56b2-b7b3-7fa7e63c3ecf",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00765164-56b8-5a8d-91e9-dd6dc447a621",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:439590c2-2d0d-5e18-ae76-b76809ccebaf",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d80bdc9b-afbc-5a8a-9a27-38ee8422d64e",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:470ef8ba-58e0-5e79-a52b-90994ba76025",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b09a51f0-0832-5b46-a4d2-be875ee2493e",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf7c7cc3-852d-5837-9e05-a2187ee2d593",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9123ea49-5e27-5ee1-b82f-e23f1ade21ff",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a7808e7-7cb1-528b-9534-48ed647ed73e",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e9ab24-66cb-5022-be56-3e42478903e4",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@10.0.26-tuxcare.2"
    }
  ]
}