{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a23bc1b7-0170-500f-97fc-9a84db001286",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-xml",
      "version": "10.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:467eb142-c4bb-568b-973b-30e69c89cc01",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18e6d377-6ce8-57ff-acb8-96888f22e895",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2076e127-826c-54ab-a9f7-aba96a3a032a",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbbd5ed8-3a4c-5efd-945f-f004c7506be7",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93917714-de98-5595-99fb-a58acfb7f834",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae32d2d1-67a9-539f-9534-6472fdf27e81",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5491f390-1e3a-56d8-97e0-b42e712b8fae",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02063e21-dfcf-5886-82b9-5df495148987",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41fc3439-8bcb-5fb5-9a78-ff5593f8dd1a",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccb0d0aa-8472-5f6e-9142-d4f2a737bed2",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38fc5a24-98d2-53c7-9e0d-61647128ab87",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78def0ed-955a-56c4-beb2-01272b109133",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf10258f-bb31-5f6b-ac4e-b03dd6672799",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d0e5e47-6eb2-5550-8948-7d0d2fc86e7a",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a1fe16c-1b62-5698-8e15-77ee80e09cb3",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a8ecc8-490a-5f34-9829-bf87b133d603",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d49c530-0621-5aa2-bcb9-96a02f101159",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e77c86-110f-56a6-8c4a-63d3cb349e1a",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3357c23-7705-5c8a-8036-7e1987816169",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b420d9ce-acaf-5240-adb0-5b7a12b292a5",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:676e72a4-3d50-5c4d-8425-da12e5b1412e",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5802327-f5d7-5ff3-a989-b74050ff1b70",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.2 of org.eclipse.jetty:jetty-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-xml@10.0.26-tuxcare.2"
    }
  ]
}