{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d56c33cf-6980-5838-85a7-636b36cbf8cd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "infinispan-remote",
      "version": "10.0.26-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:370c759b-c825-5cec-baf7-c1b828f89c6b",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95ead779-19e5-5bc3-acd4-e397a19b696f",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79842f9e-9020-5857-9b7c-fe8c765fdce3",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fcd8ea7-30e9-5f36-bdfe-6aa03527fdc9",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:484aabb9-6863-5433-8a0d-10ee853fa3cc",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9799790b-5e50-5e5e-9926-423cc6374401",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62fc4224-d6c0-51bb-8773-3eca632443d4",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:133d72b8-193a-5914-8b86-f853137f1067",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7667e231-0103-53d7-b5f1-af3f4fdedf74",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be1b11a6-ff1a-5f1b-97b5-627e1b938c70",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc77083-b670-5aa8-90a5-6c4809b3de5c",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b482e142-1f36-518a-8e99-fc349a4241a9",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b893a7-60d2-5561-9e00-6ac6004f4151",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8520b6d7-31c6-524c-856b-eb11824df775",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74fd9a7-007c-520f-9d05-f72d0df66b74",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6693265-f3e5-5c32-9efe-7dd53426a533",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a15e00cf-9c4a-590c-9047-a15b88be58e7",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efcd7213-e622-5c05-a1ad-9843ef82ec40",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcf455bc-9ff9-5b63-b9e3-e65cbb4430cf",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65d76601-59d2-524b-badc-1138930065e5",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ec84ce-2c81-5108-b1a1-359c29090a50",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92be10c-0424-5f97-8c40-00437eadf9eb",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:infinispan-remote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote@10.0.26-tuxcare.1"
    }
  ]
}