{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fa781f0e-37c4-5dd9-8421-43a5e80f107d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.demos",
      "name": "demo-mock-resources",
      "version": "10.0.26-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:52de739f-140e-5663-b0c3-3ce7aaa71400",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e091a6c-0905-54cc-bbc0-901e7aeb89ed",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6ae3a2-89f5-5977-860a-d60a7d788cda",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b11ccc-bfb7-56f2-a7cd-48dcbee5ca93",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb82f7f-bea8-5ea9-906d-f3bbe0921cdf",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9df5a5-5d05-5461-b8df-cf970e2c7870",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e659cc-8968-5829-8233-c83fd6c16ba0",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d455068-bea3-5410-a211-bf998f54204b",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc1c16e-6aef-53e5-89a7-00d992aee636",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dff8e01e-bb83-57f7-99d7-bdacbd523b23",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b9b7f2b-6869-5907-8996-2ef1f41a676b",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c787ce4d-eb19-50b3-8be1-c6049de00f1f",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:829e0810-b4fc-5094-a0b7-0fb86e4ccc3c",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:992b22c0-3e15-5f15-a0fb-b0c8fae4f480",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fed2628-38e7-500b-82b6-cc6c7bd5c28d",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8354fc81-478a-5580-9cd2-b213d25256cd",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc0f0567-a4b1-5111-b5c6-5758d7279420",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4527558a-6bca-54c6-8ed6-4ce2e03f7510",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eee61db-6fa8-588e-9173-bc9faeb0dcfe",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfc8fa4-e425-5a7a-bd32-fc2dcd15d55e",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f69f8d53-b02a-5a93-9afe-7f19e961537f",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34231fb9-6483-5bd4-a996-aed4fef6ea68",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-mock-resources."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.demos/demo-mock-resources@10.0.26-tuxcare.3"
    }
  ]
}