{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5330dd9a-5b68-5e27-97c8-003fb7cf148e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-start",
      "version": "10.0.26-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bbe42427-ae8b-53a1-8261-b288a831d585",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2357bd17-a1c7-5aaf-9ace-b4aad0a2dc91",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134d7cd2-017b-5628-8fb7-1a0a4b559458",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0157a027-f00f-5982-aca4-198ebd37322c",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:220163de-d2cf-55f1-a771-d8d25b948c27",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:534cec17-90fd-5fde-bb71-470bcb0a9ce2",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d968912-a7cb-5ed5-9fbd-56f1c51279c9",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84927cf5-b68d-5acf-82d8-323dd255b260",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:334e0ee5-3107-5700-bac8-2c712e0f3a18",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d6fc21-bc9f-596e-b261-07bfdf03a644",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e426ca7e-3a45-5b07-9dc6-d08731baffc2",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c643a15-ea7f-533b-bd76-aebdae002e26",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb52ba2-610d-51ae-9923-d6f68f6dda88",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8fe8e6-4f7b-5647-8cf0-1d004e2f2479",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b865fa96-1eb2-50c3-b481-0d82d8162f5c",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6e5dbd8-0511-5471-bc48-da00409f8323",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e0fcd74-4341-57de-a741-3e716bd6c8fc",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25fa1a42-a131-5e0a-876f-54be696c2aae",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b629c737-f6b9-5329-a98f-c8e7f7dd7d90",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f002dacb-6884-5150-84cd-0b0374284127",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf4ff7f3-3cea-57ad-9b69-754d40a7e3a5",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e7fa9f5-21a5-5504-84e2-7b8fc6fdc481",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-start."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-start@10.0.26-tuxcare.1"
    }
  ]
}