{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b3ac3c61-05b1-5521-bd15-809d06e723bc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.demos",
      "name": "demo-spec-webapp",
      "version": "10.0.26-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f40804ac-c2dd-5d39-9ac7-8e6abeb2eb44",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9d4a790-4751-5303-87a3-7dd8d5384605",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b098bb6-1fbf-5bee-aaf5-fbabbf58c2ce",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17a99e0-9c24-5ab0-8413-e7a085459458",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2297b2f9-7834-5f6e-8b08-077509c8ccd7",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3aa7e34-90a1-55ea-876c-a061eaf8f992",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:026c30c0-f0f3-5315-95fd-e4796f006b8d",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfa9a618-ec4a-5ef1-84bb-4e22db68a260",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:784281af-f62d-58cf-9723-f8bbdfafcad4",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55be9d1-6889-5504-9d6f-94f9c453ff23",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fccbde3f-cf55-56bd-8822-5fcb621c9666",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7f5bd63-c454-5002-8778-102eb3596e85",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4c2689-5013-5f29-a303-829ec0a3fe90",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbca7092-0502-586a-babc-de08cd0a0cf9",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3e20b95-92f1-5e6c-9b7c-cb1e0f935c86",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26598b8b-e7b0-5ccb-8b7c-d39951510ce2",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94e333f3-0d8c-567e-a6eb-02380bc4cbea",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85f6614e-0d92-53d0-8e86-c04a6fc4ab14",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7b52649-b038-52cd-98bc-a88f64468796",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fae256c-3414-5423-895d-f31033184f74",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b56e43b8-30c0-59bd-affb-386a2b7a830f",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a2bca64-d25f-55ec-9aaf-5376f0c7146e",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demo-spec-webapp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.demos/demo-spec-webapp@10.0.26-tuxcare.3"
    }
  ]
}