{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:68969a2d-37c0-5758-a510-a33ef0c9c3b8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty.demos",
      "name": "demo-proxy-webapp",
      "version": "11.0.19-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e20022e5-83c1-5f6f-9c0f-0706ffbfc4f1",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730a5dc8-ca19-5565-aff9-b3f520d2d929",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7fce58c-0218-51ef-bf40-3454e978128e",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb047901-bb69-5288-9e3c-370074c5402d",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf0cc79-9961-5006-8a77-f302b8ce378a",
      "id": "CVE-2024-7708",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-7708 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0fc6e90-7cdc-5c5e-ae86-5e95bd0ab279",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba3905a7-0548-595e-83b1-8e8e51a33b47",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3115e922-84c7-504d-b8b9-857706f86629",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356f92f2-8574-59c2-8483-2d3bf1570350",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12197eb9-0e8b-5d5f-9548-be22b7f4a739",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp. not_affected \u2014 Jetty 11.0.19 is not affected by CVE-2026-10051 (HTTP trailer cross-request leakage). The target version has a fundamentally different architecture from the vulnerable Jetty 12. In Jetty 11, the `_trailers` field is managed in `HttpChannelOverHttp.java` and is reliably reset to null in the `recycle()` method, which is called after each HTTP request completes. This architectural defense prevents..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac0e67f1-f5b8-567d-b0e7-86a60071e2d3",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp. Version 11.0.19 is not vulnerable. Summary: Target repository is Jetty 11.0.19, which is not affected by CVE-2026-1605. This CVE specifically affects Jetty 12.x (versions 12.0.0-12.0.31 and 12.1.0-12.1.5). Jetty 11 uses a fundamentally different architecture where request decompression resource cleanup is properly tied to the request lifecycle via HttpInput.recycle(), not to response compression status. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:647fa84b-5ea9-5154-8787-34a0a6108db5",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea490ffe-67e8-58af-aa1f-fe37adfbac88",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4165fee-165c-5f40-a3b1-a57caf064b06",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63bdcf8d-c6c5-50d8-bd2b-fc027f6d7a38",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp. not_affected \u2014 Jetty 11.0.19 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.x due to architectural changes where canonicalPath() processes encoded paths directly with semicolon handling. Version 11.x uses a two-step process (decodePath then canonicalPath) that correctly normalizes paths like /public;/../admin/secret to /admin/secret, preventing security constraint bypass."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f1be506-19c4-58cb-9234-3cb25ea5f64b",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 11.0.19-tuxcare.1 of org.eclipse.jetty.demos:demo-proxy-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.demos/demo-proxy-webapp@11.0.19-tuxcare.1"
    }
  ]
}