{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5b2ae28d-16c3-512c-96ad-2fd4e134721f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-keystore",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ccf8c6d1-12ac-58ca-aae8-27dce9279dbc",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0affbbb-8cd3-5eba-93ba-9f7678c8eccc",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59cc456c-1f57-5fa1-b942-00e8ee5ba8bf",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87755f90-532a-5ec5-bf61-30cffe95993c",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6324b51e-d71c-53f4-9369-ab09a2331896",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc01e10d-199a-596e-a5c1-bc1e53cf7c0f",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0581472-55f7-52b8-a7c2-b9bf03c6423e",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e1c168e-e53a-58d9-8c33-855927e82389",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59fc415e-3377-5f0f-b48a-ca51e3cb9d0a",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4524036-261e-55ce-8d33-2da5cd54420d",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:933a971d-eb0e-51f5-ad10-e9aaec37beae",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de3a5d23-1a98-54bd-b299-46110f5c05df",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6cc816-63db-55cf-a291-ac1751766efa",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b59ab25-8292-57a6-a15f-ce5d0b3d2ac1",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58bca85-4dcb-53af-9992-967b26d6dc80",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dd53782-a693-5cc4-88e2-d448be3895d1",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b90bd78e-62b9-5097-a735-c5dd05f7ad1d",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd987c7-8e62-52b6-a1c8-cd5d852090cb",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15b19587-bb20-5a6f-bf81-d9dd9a4677bb",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bce0bb5-d1d5-5091-b3f6-adb66fe72cde",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:676b3a93-f7ba-509d-b4e2-f7df0838b845",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdcbcb6c-4182-52b4-b6b7-2107cca90d69",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-keystore."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-keystore@10.0.26-tuxcare.2"
    }
  ]
}