{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13afb952-1da5-573b-9fb8-3864ca0266cf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-security",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:35947370-e656-591c-a97f-e84f549cb8a2",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:239cd279-a048-5591-bf34-f0006c21057e",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ca988a-d123-50fd-9a9b-609f789a1284",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aa4a148-0d57-5eb7-bb26-27bd896a2137",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e1e1edf-7fba-5761-ac8a-ef62c3ce338c",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8adcdac6-f4d5-550a-9a87-e4730fcde4ae",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf1bb849-636a-5d12-bc8a-dca63e216e93",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf6039f8-7f49-5490-890b-97b190fb70c3",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:203a5341-6f96-5516-8336-883ecefc7c83",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08edc3dc-f47c-588b-9dcd-e4f63bd6d57a",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3679c70-eeca-5c39-a984-55ff9eb93339",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11599a30-246d-5a42-9f58-a397c62ddc1b",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1201c827-e89e-5f52-adb3-dc6e6983342f",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d9e3fa0-394e-50a6-b258-06406f3e2852",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99fa456-2437-5e23-acb3-f1a2935e2697",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6329d35b-c882-5b09-b5f9-ba9d830d9b10",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66dc9fe7-12a7-50ae-bfce-e6b8de35d1e5",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0aee438-2fd0-5671-8f61-9d2c4e91a3fa",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:540a6807-520e-5395-b0bb-0433726ba8c6",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e34e26d8-2f3e-503a-a611-1c3719bda8a1",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d4530fc-c785-54ce-bfc3-ba4b06222dd2",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cad15c1-2336-51e2-baa9-2f747f15e2ef",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-security@10.0.26-tuxcare.2"
    }
  ]
}