{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6d4ce08c-10b1-5ab7-84b6-a49fcc6278c8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.demos",
      "name": "demo-jndi-webapp",
      "version": "10.0.26-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7bbfd4f9-efe5-5a8d-8b93-a5d1c60f24ed",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf5d6841-f8c2-5447-aa9b-6c47030f28ed",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a5a8b2-9b5f-52cc-b349-86cc6c8b5fa0",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde2b8a7-393a-5926-ac74-19f50d455d20",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d182a1b2-ea47-589d-b0cc-633deebba7bb",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7804a898-cd83-5439-8afd-0e260c7550e4",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55778478-764f-56d4-88ac-7c3ea8b60504",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e1e9357-1e0c-5849-897b-d6760e37cc51",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a799c9-5967-5bea-a5ce-c9a72810e09f",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:425c3c23-4405-5337-99ff-17ccd5a14ab1",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fada294f-704e-57f3-bb1e-a21d6fd39b3f",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c6d0e2f-e5fb-5274-97b4-c984232ad66e",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca1550a0-a1d9-53de-82d2-9a243b29cc53",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a4f8e47-1758-5443-8fe7-5f2b38f2223c",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea15162a-1f26-599a-9da3-23a665ac962c",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb6c9ff-3639-5b63-bee6-58e5b2fb4289",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4995be18-790d-5395-9b74-04c77ff855d7",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e554a61-3f56-55e6-94e7-94663b31b7f9",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85c26819-2cd2-558d-9cf1-2f00701e7815",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1492caf-3fd1-55a8-a6df-b39db49ff902",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc7c07f-3936-52ce-baa9-7b5bbf48de36",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20d561f5-76c6-59f6-a4d6-8e921bedd6aa",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-jndi-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.demos/demo-jndi-webapp@10.0.26-tuxcare.3"
    }
  ]
}